VaronisSaaS
Streamline alerts and related forensic information from Varonis SaaS.
- Category
- Analytics & SIEM
- Pack
- VaronisSaaS
Configuration parameters
- isFetch — Fetch incidents
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- url — The FQDN/IP the integration should connect to (required)
- apiKey — (required)
- proxy — Use system proxy settings
- insecure — Trust any certificate (not secure)
- max_fetch — Maximum number of incidents per fetch
- first_fetch — First fetch time
- severity — Minimum severity of alerts to fetch
- threat_model — Varonis threat model name
- status — Varonis alert status
- mirror_direction — Incident Mirroring Direction
Commands (8)
- get-mapping-fields — Returns the list of fields to map in outgoing mirroring. This command is only used for debugging purposes.
- update-remote-system — Updates the remote incident with local incident changes. This method is only used for debugging purposes and will not update the current incident.
- varonis-alert-add-note — Add note to alerts.
- varonis-close-alert — Close the alert.
- varonis-get-alerted-events — Get events applied to specific alerts.
- varonis-get-alerts — Get alerts from Varonis DA.
- varonis-get-threat-models — Get Varonis threat models.
- varonis-update-alert-status — Update alert status.