Stealthwatch Cloud
Protect your cloud assets and private network.
- Category
- Network Security
- Pack
- Stealthwatch_Cloud
Configuration parameters
- serverURL — Stealthwatch's server URL (required)
- APIKey — Stealthwatch Cloud API key. Should be in the form of "ApiKey <username>:<apikey>"
- credentials_api_key —
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
Commands (8)
- sw-block-domain-or-ip — Add a domain or IP to the block list
- sw-list-alerts — Get the list of Stealthwatch alerts
- sw-list-blocked-domains — Returns list of the blocked domains
- sw-list-observations — Get observations by alert ID, observation ID, or free search
- sw-list-sessions — Get sessions by the session's occurrence time ( Time format: YYYY-MM-DDTHH:MM:SSZ)
- sw-show-alert — Get info about a specific alert by its ID
- sw-unblock-domain — Remove a domain from the block list
- sw-update-alert — Update an alert