McAfee ESM-v10
Deprecated. Use the McAfee ESM v2 integration instead.
- Category
- Analytics & SIEM
- Pack
- McAfee_ESM-v10
Configuration parameters
- ip — ESM IP (e.g. 78.125.0.209) (required)
- port — Port (required)
- credentials — Username (required)
- version — Version: (one of 10.0, 10.1, 10.2, 10.3, 11.1) (required)
- insecure — Trust any certificate (not secure)
- time_format — ESM time format, e.g., %Y/%m/%d %H:%M:%S. Select "auto-discovery" to attempt to determine the format automatically.
- isFetch — Fetch incidents
- incidentType — Incident type
- fetchTypes — Fetch Types: cases, alarms, both (relevant only for fetch incident mode)
- startingCaseID — Start fetch after Case ID: (relevant only for fetch incident mode)
- alarm_fetch_time — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- timezone — McAfee ESM Timezone in hours (e.g if ESM timezone is +0300 => then insert 3)
Commands (19)
- esm-acknowledge-alarms — Mark triggered alarms as acknowledged
- esm-add-case — Add a case to the system
- esm-add-case-status — Add a case status
- esm-delete-alarms — Delete triggered alarms
- esm-delete-case-status — Delete a case status
- esm-edit-case — Edit an existing case
- esm-edit-case-status — Edit a case status
- esm-fetch-alarms — Retrieves a list of alarms that have been triggered
- esm-fetch-fields — Get all fields that can be used in query filters, with type information for each field
- esm-get-alarm-event-details — Gets the details for the triggered alarm
- esm-get-case-detail — Get detail on an existing case
- esm-get-case-event-list — Get case events details
- esm-get-case-list — Get a list of cases from the system
- esm-get-case-statuses — Get a list of valid case statuses from the system
- esm-get-organization-list — Get case organization
- esm-get-user-list — Get a list of all users.
- esm-list-alarm-events — Gets an event list related to the alarm
- esm-search — Perform a query against Mcafee ESM SIEM
- esm-unacknowledge-alarms — Mark triggered alarms as unacknowledged