SailPointIdentityNowEventCollector
This is the SailPoint IdentityNow event collector integration for Cortex XSIAM.
- Category
- Analytics & SIEM
- Pack
- SailPointIdentityNow
Configuration parameters
- url — IdentityNow Server URL (e.g., https://{tenant}.api.identitynow.com) (required)
- credentials — Client ID (required)
- limit — Max number of events per fetch
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- look_back — Minutes to look back when fetching
Commands (1)
- identitynow-get-events — Gets events from SailPoint IdentityNow. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to event duplication and exceeding API request limitations.