LogRhythm
Deprecated. Use the LogRhythmRest v2 integration instead.
- Category
- Analytics & SIEM
- Pack
- LogRhythm
Configuration parameters
- Host — Hostname, IP address or Server URL (required)
- Credentials — Credentials (required)
- Insecure — Trust any certificate (not secure)
- useproxy — Use system proxy settings
- isFetch — Fetch incidents
- pageSize — Default page size for alarm queries
- timeZone — Timezone offset in minutes of the LogRhythm server machine
- incidentType — Incident type
- use_ntlm — Use Windows Authentication
- domain — Domain of the Windows authentication server (used for Windows authentication)
Commands (9)
- lr-add-alarm-comments — Update alarm with comments
- lr-add-host — Adds a new host to an entity.
- lr-execute-query — Executes a query for logs that match query parameters.
- lr-get-alarm-by-id — Retrieve a single alarm by the unique alarm identifier
- lr-get-alarm-events-by-id — Retrieve a list of events associated to this alarm
- lr-get-alarm-history-by-id — Retrieve a list of alarm status and comment updates
- lr-get-alarms — Retrieve alarms in the specified time period. Alerts can be filtered by the alarm status.
- lr-get-hosts-by-entity-id — Retrieves a list of hosts for a given entity, or an empty list if none is found.
- lr-update-alarm-status — Update alarm status