ProtectWise
Cloud based Security Network DVR.
- Category
- Network Security
- Pack
- ProtectWise
Configuration parameters
- url — Url (required)
- email — Email
- password — Password
- credentials_login — Email
- token — API Token
- credentials_api_token —
- insecure — Trust any certificate (not secure)
- messageFilter — Only fetch events with this text in the name
- threatCategory — Filter by threat category
- killChainStage — Filter by killchain stage
- threatLevel — Filter by threat level (LOW, MEDIUM, or HIGH)
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- proxy — Use system proxy settings
- maxFetch — Maximum events to fetch per fetch
Commands (19)
- event-pcap-download — The Event PCAP file to download.
- event-pcap-info — Returns details of the ProtectWise Event PCAP files.
- get-token — Returns the API token, which is used in the integration configuration.
- observation-pcap-download — Downloads the observation PCAP file.
- observation-pcap-info — Returns PCAP details of observations in Protectwise.
- observation-search — Searches for observations in ProtectWise.
- protectwise-event-info — Searches for a single event in ProtectWise. Deprecated - use the protectwise-event-info command.
- protectwise-event-pcap-download — Event Pcap Download. Deprecated - use the protectwise-event-pcap-info command.
- protectwise-event-pcap-info — Get ProtectWise Event Pcap info. Deprecated - use the protectwise-observation-pcap-download command.
- protectwise-observation-info — Lookup a single observation for ProtectWise. Deprecated - use the protectwise-event-pcap-download command.
- protectwise-observation-pcap-download — Downloads the Observation PCAP file. Deprecated - use the protectwise-observation-pcap-info command.
- protectwise-observation-pcap-info — Returns ProtectWise Observation PCAP file information.
- protectwise-search-events — Searches for events. Events are resources that describe a threat and contains a collection of observations. Deprecated - use the protectwise-search-events command.
- protectwise-search-observations — Searches for observations in ProtectWise. Deprecated - use the protectwise-search-observations command.
- protectwise-show-sensors — Returns all available sensors.
- pw-event-get — Returns information about a single event and its associated observations.
- pw-observation-get — Searches for a single observation in ProtectWise.
- search — Searches for events. Events are resources that describe a threat and contain a collection of observations.
- sensors — Returns the specified, or all available sensors.