LogRhythmRest
LogRhythm security intelligence.
- Category
- Analytics & SIEM
- Pack
- LogRhythmRest
Configuration parameters
- url — Hostname, IP address, or server URL (required)
- token — API Token
- credentials_api_token —
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- cluster-id — Search API cluster ID
- entity-id — Entity ID
- isFetch — Fetch incidents
- incidentFetchInterval — Incidents Fetch Interval
- incidentType — Incident type
Commands (18)
- lr-add-host — Add a new host to an entity.
- lr-add-login — Add a new login to the LogRhythm user
- lr-add-user — Add a new user to the LogRhythm SIEM
- lr-execute-query — Executes a query for logs that match the query parameters.
- lr-execute-search-query — Execute search query to LogRhythm log database.
- lr-get-alarm-data — Returns data for an alarm.
- lr-get-alarm-events — Returns a list of events, by alarm ID.
- lr-get-case-evidence — Execute evidence query for a specific case ID.
- lr-get-hosts — Returns a list of hosts.
- lr-get-hosts-by-entity — Retrieves a list of hosts for a given entity, or an empty list if none is found.
- lr-get-logins — Returns a list of logins
- lr-get-networks — Retrieves a list of networks.
- lr-get-persons — Retrieves a list of LogRhythm persons.
- lr-get-privileges — Returns the privileges of a given user.
- lr-get-profiles — Returns a list of user profiles
- lr-get-query-result — Get search query result for the specified task ID. The task ID can be retrieved from the lr-execute-search-query command.
- lr-get-users — Returns a list of users
- lr-update-host-status — Updates a host status.