Symantec Advanced Threat Protection
Deprecated. No available replacement.
- Category
- Endpoint
- Pack
- Symantec_Advanced_Threat_Protection
Configuration parameters
- url — Server URL (i.e. https://host:port) (required)
- client — Client ID as generated in the ATP console (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- fetch_incidents_type — Incident data source
- max_fetch — Maximum number of events per fetch.
- isFetch — Fetch incidents
- incidentType — Incident type
- first_fetch — First fetch timestamp (<number> <time unit>, e.g., 12 hours, 7 days). Maximum is 30 days.
- fetch_incidents_query — Query string for fetch incidents. For example - "updated>='2020-06-06T15:39:55.616Z' and updated<'2020-08-07T00:00:00.000Z' "
Commands (8)
- satp-appliances — Retrieve the appliances configured with the versions
- satp-command — Issue commands to endpoints managed by Symantec Endpoint Protection
- satp-command-cancel — Cancel the given command
- satp-command-state — Retrieve the command state
- satp-events — Accepts search requests over a specified time range and returns events that match the search condition. You must specify the time range using the start_time parameter and the end_time parameter (the maximum time range is 7 days). The time in the result schema and is typically the event creation time. This API supports search conditions (such as logical operators and special characters) to narrow the events to be retrieved. See examples at https://help.symantec.com/api-doc/atp_2.2/EN_US/#_events_query_api_example.
- satp-files — Retrieve details about file based on given hash
- satp-incident-events — Get events that are related to incidents
- satp-incidents — Query incidents from ATP