StellarCyber
Fetches and mirrors in Cases from Stellar Cyber to XSOAR. In addition, provides a command to update Case severity/status/assignee/tags, and a command to query an Alert.
- Category
- Analytics & SIEM
- Pack
- StellarCyber
Configuration parameters
- isFetch — Fetch incidents
- incidentType — Incident type
- mirror_direction — Mirroring Direction
- stellar_dp — Stellar Cyber Host (e.g. example.stellarcyber.cloud) (required)
- credentials — API User (Email Address) (required)
- first_fetch — First fetch time
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- incidentFetchInterval — Incidents Fetch Interval
- tenantid — Optional - Tenant ID
- max_fetch — Maximum number of incidents per fetch
Commands (4)
- get-modified-remote-data — Available from Cortex XSOAR version 6.1.0. This command queries for incidents that were modified since the last update. This method is only used for debugging purposes.
- get-remote-data — Gets remote data from a remote incident. This method is only used for debugging purposes and will not update the current incident.
- stellar-get-alert — Retrieve an alert from Stellar Cyber.
- stellar-update-case — Update the severity, status, assignee, or tags of a Case in Stellar Cyber.