VectraRUXEventsDetections
This integration allows the security operations center to create and manage incidents based on Vectra Events Detections.
- Category
- Network Security
- Pack
- VectraRUX
Configuration parameters
- server_url — Server URL (required)
- credentials — Client ID (required)
- isFetch — Fetch incidents
- max_fetch — Max Fetch
- first_fetch — First Fetch Time
- entity_types — Entity Types
- only_prioritized_detections — Create Incidents for Prioritized Detections
- only_escalated_detections — Create Incidents for Escalated Detections
- mirror_direction — Mirroring Direction
- note_tag — Mirror tag for notes
- open_detection_on_incident_reopen — Open Detection on Incident Reopen
- detection_status_for_reopen — Detection Status for Incident Reopen
- close_detection_on_incident_closure — Close Detection on Incident Closure
- close_reason_of_detection — Detection Close Reason for Incident Closure
- incidentType — Incident type
- incidentFetchInterval — Incidents Fetch Interval
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (36)
- vectra-assignment-list — Returns a list of all assignments.
- vectra-detection-describe — Returns a list of detections for the specified detection ID(s).
- vectra-detection-external-id-update — Update the external reference ID for the provided detection ID(s).
- vectra-detection-investigation-status-update — Update the investigation status of the detection by detection ID(s).
- vectra-detection-list — Returns a list of detections based on the specified filters.
- vectra-detection-note-add — Add a note to the detection.
- vectra-detection-note-list — Returns a list of notes for a specified detection.
- vectra-detection-note-remove — Remove a note from the detection.
- vectra-detection-note-update — Update a note in the detection.
- vectra-detection-pcap-download — Download pcap of the detection.
- vectra-detection-tag-add — Add tags to a detection.
- vectra-detection-tag-list — Returns a list of tags for a specified detection.
- vectra-detection-tag-remove — Remove tags from the detection.
- vectra-detections-mark-asclosed — Mark detections as closed with provided detection IDs in the argument.
- vectra-detections-mark-asopen — Open detections with provided detection IDs in the argument.
- vectra-entity-assignment-add — Add an assignment for the entity.
- vectra-entity-assignment-update — Update an assignment in the entity.
- vectra-entity-describe — Describes an entity by ID.
- vectra-entity-detection-list — Returns a list of detections for a specified entity.
- vectra-entity-detections-mark-asclosed — Mark the detections of the entity as closed with the provided entity ID in the argument.
- vectra-entity-external-id-update — Update the external reference ID for the provided entity.
- vectra-entity-list — Returns a list of entities.
- vectra-entity-note-add — Add a note to the entity.
- vectra-entity-note-list — Returns a list of notes for a specified entity.
- vectra-entity-note-remove — Remove a note from the entity.
- vectra-entity-note-update — Update a note in the entity.
- vectra-entity-tag-add — Add tags in the entity.
- vectra-entity-tag-list — Returns a list of tags for a specified entity.
- vectra-entity-tag-remove — Remove tags from the entity.
- vectra-entity-unresolved-priority-reset — Update the unresolved priority of an entity to false.
- vectra-group-assign — Assign members to the specified group.
- vectra-group-list — Returns a list of all groups.
- vectra-group-unassign — Unassign members from the specified group.
- vectra-investigation-query-send — Submit an investigation query and receive a request ID for retrieving results.
- vectra-investigation-result-get — Retrieve the results of a previously submitted investigation query using the request ID.
- vectra-user-list — Returns a list of users.