WALLIX Bastion
Centralized Control and Monitoring of Privileged Access to Sensitive Assets.
- Category
- Authentication & Identity Management
- Pack
- WALLIXBastion
Configuration parameters
- url — Server URL (e.g. localhost) (required)
- auth_user — API Auth User (required)
- auth_key — API Auth Key or user password
- is_password — Password authentication mode (set false if you provided an API key)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- api_version — API version to use. Leave the field empty to use the latest API version available.
- timeout — API requests timeout in seconds. The default value is 60 seconds.
Commands (188)
- wab-add-account-in-global-domain — Add an account in a global domain category: Domain Accounts.
- wab-add-account-to-local-domain-of-application — Add an account to a local domain of an application category: Application Accounts.
- wab-add-account-to-local-domain-on-device — Add an account to a local domain on a device category: Device Accounts.
- wab-add-authorization — Add an authorization category: Authorizations.
- wab-add-connection-policy — Add a connection policy category: Connection Policies.
- wab-add-credential-to-application-account — Add a credential to an application account on a local domain category: Application Account Credentials.
- wab-add-credential-to-device-account — Add a credential to a device account on a local domain category: Device Account Credentials.
- wab-add-credential-to-global-domain-account — Add a credential to a global domain account category: Domain Account Credentials.
- wab-add-device — Add a device category: Devices.
- wab-add-global-domain — Add a global domain category: Domains.
- wab-add-local-domain-in-application — Add a local domain in an application category: Application Local Domains.
- wab-add-local-domain-in-device — Add a local domain in a device category: Device Local Domains.
- wab-add-mapping-in-domain — Add a mapping in a domain and set mapping fallback. If the field "external_group" is set to "*", it is used as the fallback mapping, which allows mapping of users in the domain that do not belong to the external_group to be mapped to the user_group by default category: Auth Domain Mappings.
- wab-add-mapping-in-group — Add a mapping in a group and set mapping fallback. If the field "external_group" is set to "*", it is used as the fallback mapping, which allows mapping of users in the domain that do not belong to the external_group to be mapped to the user group by default category: User Group Mappings.
- wab-add-notification — Add a notification category: Notifications.
- wab-add-password-change-policy — Add a password change policy. Note: at least password or SSH options must be given in the policy (and both can be used at same time) category: Password Change Policies.
- wab-add-password-target-to-target-group — Add a password checkout account to a target group.
- wab-add-restriction-to-target-group — Add a restriction in a targetgroup category: Target Group Restrictions.
- wab-add-restriction-to-usergroup — Add a restriction to a usergroup category: User Group Restrictions.
- wab-add-service-in-device — Add a service in a device category: Device Services.
- wab-add-session-target-to-target-group — Add a target account to a target group.
- wab-add-target-group — Add a target group category: Target Groups.
- wab-add-timeframe — Add a timeframe category: Timeframes.
- wab-add-timeframe-period — Add a period to a timeframe category: Timeframes.
- wab-add-user — Add a user category: Users.
- wab-add-user-group — Add a user group category: User Groups.
- wab-cancel-accepted-approval — Cancel an accepted approval. Note: you can cancel an approval only if you are in approvers groups of authorization and the end date is still not reached category: Approvals Assignments.
- wab-cancel-approval-request — Cancel an approval request category: Approvals Requests.
- wab-cancel-scan-job — Cancel a scan job category: Scan Jobs.
- wab-change-password-or-ssh-key-of-account — Change password or SSH key of an account and propagate changes on the target host. If the body is empty, an automatic password change is performed: the password or the SSH key are changed to a newly generated value, according to the password change policy on the domain. Note: the password change must be enabled on the domain, with a plugin that will be used to change the password on the target host category: Account Change Password.
- wab-check-if-approval-is-required-for-target — Check if an approval is required for this target (optionally for a given date in future) category: Approvals Requests Target.
- wab-create-session-request — Create a session request category: Sessions Requests.
- wab-delete-account — Delete an account category: Accounts.
- wab-delete-account-from-global-domain — Delete an account from a global domain category: Domain Accounts.
- wab-delete-account-from-local-domain-of-application — Delete an account from a local domain of an application category: Application Accounts.
- wab-delete-account-from-local-domain-of-device — Delete an account from a local domain of a device category: Device Accounts.
- wab-delete-application — Delete an application category: Applications.
- wab-delete-authorization — Delete an authorization category: Authorizations.
- wab-delete-connection-policy — Delete a connection policy. Note: it is not possible to delete the default Bastion connection policies category: Connection Policies.
- wab-delete-device — Delete a device category: Devices.
- wab-delete-global-domain — Delete a global domain category: Domains.
- wab-delete-local-domain-from-application — Delete a local domain from an application category: Application Local Domains.
- wab-delete-local-domain-from-device — Delete a local domain from a device category: Device Local Domains.
- wab-delete-mapping-of-domain — Delete the mapping of the given domain category: Auth Domain Mappings.
- wab-delete-mapping-of-user-group — Delete the mapping of the given user group category: User Group Mappings.
- wab-delete-notification — Delete a notification category: Notifications.
- wab-delete-password-change-policy — Delete a password change policy category: Password Change Policies.
- wab-delete-pending-or-live-session-request — Delete a pending or a live session request category: Sessions Requests.
- wab-delete-resource-from-global-domain-account — delete a resource from the global domain account category: Domain Accounts.
- wab-delete-restriction-from-targetgroup — Delete a restriction from a targetgroup category: Target Group Restrictions.
- wab-delete-restriction-from-usergroup — Delete a restriction from a usergroup category: User Group Restrictions.
- wab-delete-scan — Delete a scan category: Scans.
- wab-delete-service-from-device — Delete a service from a device category: Device Services.
- wab-delete-target-from-group — Delete a target from a group category: Target Groups.
- wab-delete-target-group — Delete a target group category: Target Groups.
- wab-delete-timeframe — Delete a timeframe category: Timeframes.
- wab-delete-user-group — Delete a user group category: User Groups.
- wab-edit-account-in-global-domain — Edit an account in a global domain category: Domain Accounts.
- wab-edit-account-on-local-domain-of-application — Edit an account on a local domain of an application category: Application Accounts.
- wab-edit-account-on-local-domain-of-device — Edit an account on a local domain of a device category: Device Accounts.
- wab-edit-application — Edit an application category: Applications.
- wab-edit-authorization — Edit an authorization category: Authorizations.
- wab-edit-connection-policy — Edit a connection policy category: Connection Policies.
- wab-edit-credential-of-application-account — Edit a credential of an application account on a local domain category: Application Account Credentials.
- wab-edit-credential-of-device-account — Edit a credential of an account on a local domain of a device category: Device Account Credentials.
- wab-edit-credential-of-global-domain-account — Edit a credential of a global domain account category: Domain Account Credentials.
- wab-edit-device — Edit a device category: Devices.
- wab-edit-mapping-of-domain — Edit a mapping of a domain category: Auth Domain Mappings.
- wab-edit-mapping-of-user-group — Edit a mapping of a user group category: User Group Mappings.
- wab-edit-mappings-of-domain — Edit mappings of a domain category: Auth Domain Mappings.
- wab-edit-notification — Edit a notification category: Notifications.
- wab-edit-password-change-policy — Edit a password change policy category: Password Change Policies.
- wab-edit-restriction-from-targetgroup — Edit a restriction from a targetgroup category: Target Group Restrictions.
- wab-edit-restriction-from-usergroup — Edit a restriction from a usergroup category: User Group Restrictions.
- wab-edit-scan — Edit a scan category: Scans.
- wab-edit-service-of-device — Edit a service of a device category: Device Services.
- wab-edit-session — Edit a session category: Sessions.
- wab-edit-target-group — Edit a target group category: Target Groups.
- wab-edit-timeframe — Edit a timeframe category: Timeframes.
- wab-edit-user — Edit a user category: Users.
- wab-edit-user-group — Edit a user group category: User Groups.
- wab-extend-duration-time-to-get-passwords-for-target — Extend the duration time to get the passwords for a given target category: Target Passwords.
- wab-generate-trace-for-session — Generate a trace for a session category: Sessions Traces.
- wab-get-account-of-global-domain — Get the account of a global domain category: Domain Accounts.
- wab-get-account-reference — Get account reference category: Account References.
- wab-get-account-references — Get account references category: Account References.
- wab-get-accounts-of-global-domain — Get the accounts of a global domain category: Domain Accounts.
- wab-get-all-accounts — Get all accounts category: Accounts.
- wab-get-all-accounts-on-device-local-domain — Get all accounts on a device local domain category: Device Accounts.
- wab-get-application — Get the application category: Applications.
- wab-get-application-account — Get the application account category: Application Accounts.
- wab-get-application-account-credential — Get the application account credential category: Application Account Credentials.
- wab-get-application-account-credentials — Get the application account credentials category: Application Account Credentials.
- wab-get-application-accounts — Get the application accounts category: Application Accounts.
- wab-get-applications — Get the applications category: Applications.
- wab-get-approval-request-pending-for-user — Get the approval request pending for this user (by default the user logged on the REST API), or the approval request with the given id category: Approvals Requests.
- wab-get-approvals — Get the approvals category: Approvals.
- wab-get-approvals-for-all-approvers — Get the approvals for a given approver category: Approvals Assignments.
- wab-get-approvals-for-approver — Get the approvals for a given approver category: Approvals Assignments.
- wab-get-auth-domain — Get the auth domain category: Auth Domains.
- wab-get-auth-domains — Get the auth domains category: Auth Domains.
- wab-get-authentication — Get the authentication category: Authentications.
- wab-get-authentications — Get the authentications category: Authentications.
- wab-get-authorization — Get the authorization category: Authorizations.
- wab-get-authorizations — Get the authorizations category: Authorizations.
- wab-get-certificate-on-device — Get the certificate on a device category: Device Certificates.
- wab-get-certificates-on-device — Get the certificates on a device category: Device Certificates.
- wab-get-checkout-policies — Get the checkout policies category: Checkout Policies.
- wab-get-checkout-policy — Get the checkout policy category: Checkout Policies.
- wab-get-cluster — Get the cluster category: Clusters.
- wab-get-clusters — Get the clusters category: Clusters.
- wab-get-connection-policies — Get the connection policies category: Connection Policies.
- wab-get-connection-policy — Get the connection policy category: Connection Policies.
- wab-get-current-serial-configuration-number-of-bastion — Get current serial configuration number of the Bastion. This number can be used to know if the Bastion configuration was changed category: Configuration Number.
- wab-get-device — Get the device category: Devices.
- wab-get-device-account-credential — Get one credential of an account on a device local domain category: Device Account Credentials.
- wab-get-device-account-credentials — Get all credentials of an account on a device local domain category: Device Account Credentials.
- wab-get-devices — Get the devices category: Devices.
- wab-get-external-authentication — Get the external authentication category: External Authentications.
- wab-get-external-authentication-group-mappings — Get the external authentication group mappings category: Ldap Mappings.
- wab-get-external-authentications — Get the external authentications category: External Authentications.
- wab-get-global-domain — Get the global domain category: Domains.
- wab-get-global-domain-account-credential — Get the credential of a global domain account category: Domain Account Credentials.
- wab-get-global-domain-account-credentials — Get the credentials of a global domain account category: Domain Account Credentials.
- wab-get-global-domains — Get the global domains category: Domains.
- wab-get-information-about-wallix-bastion-license — Get information about the WALLIX Bastion license category: License Info.
- wab-get-latest-snapshot-of-running-session — Get the latest snapshot of a running session category: Sessions Snapshots.
- wab-get-ldap-user-of-domain — Get the LDAP user of a given domain category: Ldap Users.
- wab-get-ldap-users-of-domain — Get the LDAP users of a given domain category: Ldap Users.
- wab-get-local-domain-data-for-application — Get local domain data for a given application category: Application Local Domains.
- wab-get-local-domain-of-device — Get the local domain of a device category: Device Local Domains.
- wab-get-local-domains-data-for-application — Get local domains data for a given application category: Application Local Domains.
- wab-get-local-domains-of-device — Get the local domains of a device category: Device Local Domains.
- wab-get-mapping-of-domain — Get the mapping of a domain category: Auth Domain Mappings.
- wab-get-mapping-of-user-group — Get the mapping of a user group category: User Group Mappings.
- wab-get-mappings-of-domain — Get the mappings of a domain category: Auth Domain Mappings.
- wab-get-mappings-of-user-group — Get the mappings of a user group category: User Group Mappings.
- wab-get-notification — Get the notification category: Notifications.
- wab-get-notifications — Get the notifications category: Notifications.
- wab-get-object-to-onboard — Get object to onboard, by type (either devices with their linked accounts or global accounts alone) category: Onboarding Objects.
- wab-get-one-account — Get one account category: Accounts.
- wab-get-one-account-on-device-local-domain — Get one account on a device local domain category: Device Accounts.
- wab-get-password-change-policies — Get the password change policies category: Password Change Policies.
- wab-get-password-change-policy — Get the password change policy category: Password Change Policies.
- wab-get-password-for-target — Get the password for a given target category: Target Passwords.
- wab-get-passwordrights — Get current user's or the user 'user_name' password rights on accounts (for checkout/checkin) category: Password Rights.
- wab-get-passwordrights-user-name — Get current user's or the user 'user_name' password rights on accounts (for checkout/checkin) category: Password Rights.
- wab-get-profile — Get the profile category: Profiles.
- wab-get-profiles — Get the profiles category: Profiles.
- wab-get-scan — Get the scan category: Scans.
- wab-get-scanjob — Get the scanjob category: Scan Jobs.
- wab-get-scanjobs — Get the scanjobs category: Scan Jobs.
- wab-get-scans — Get the scans category: Scans.
- wab-get-service-of-device — Get the service of a device category: Device Services.
- wab-get-services-of-device — Get the services of a device category: Device Services.
- wab-get-session-metadata — Get the metadata of one or multiple sessions category: Sessions Metadata.
- wab-get-session-sharing-requests — Get session sharing requests category: Sessions Requests.
- wab-get-sessionrights — Get current user's or the user 'user_name' session rights (connections via proxies) category: Session Rights.
- wab-get-sessionrights-user-name — Get current user's or the user 'user_name' session rights (connections via proxies) category: Session Rights.
- wab-get-sessions — Get the sessions category: Sessions.
- wab-get-status-of-trace-generation — Get the status of a trace generation category: Sessions Traces.
- wab-get-target-by-type — Get the target by type category: Targets.
- wab-get-target-group — Get the target group category: Target Groups.
- wab-get-target-group-restriction — Get one target group restriction category: Target Group Restrictions.
- wab-get-target-group-restrictions — Get target group restrictions category: Target Group Restrictions.
- wab-get-target-groups — Get the target groups category: Target Groups.
- wab-get-timeframe — Get the timeframe category: Timeframes.
- wab-get-timeframes — Get the timeframes category: Timeframes.
- wab-get-user — Get the user category: Users.
- wab-get-user-group — Get the user group category: User Groups.
- wab-get-user-group-restriction — Get one user group restriction category: User Group Restrictions.
- wab-get-user-group-restrictions — Get user group restrictions category: User Group Restrictions.
- wab-get-user-groups — Get the user groups category: User Groups.
- wab-get-users — Get the users category: Users.
- wab-get-version — Get the REST API and WALLIX Bastion version numbers category: Version.
- wab-get-wallix-bastion-usage-statistics — Get the WALLIX Bastion usage statistics. If no from_date or to_date are supplied it will return the statistics for the last full calendar month category: Statistics.
- wab-getx509-configuration-infos — Get the X509 configuration infos category: Config X509.
- wab-make-new-approval-request-to-access-target — Make a new approval request to access a target. Note: depending on the authorization settings, the fields "ticket" and "comment" may be required category: Approvals Requests.
- wab-notify-approvers-linked-to-approval-assignment — Notify approvers linked to an approval request by sending them an email category: Approvals Assignments.
- wab-notify-approvers-linked-to-approval-request — Notify approvers linked to an approval request by sending them an email category: Approvals Requests.
- wab-post-logsiem — Write a message in /var/log/wabaudit.log and send it to the SIEM (if configured) category: Log Siem.
- wab-release-passwords-for-target — Release the passwords for a given target category: Target Passwords.
- wab-reply-to-approval-request — Reply to an approval request (approve/reject it). Note: you can answer to an approval request only if you are in approvers groups of authorization category: Approvals Assignments.
- wab-resetx509-configuration — Reset X509 configuration category: Config X509.
- wab-revoke-certificate-of-device — Revoke a certificate of a device category: Device Certificates.
- wab-start-scan-job-manually — Start a scan job manually category: Scan Jobs.
- wab-updatex509-configuration — Update X509 Configuration category: Config X509.
- wab-uploadx509-configuration — Upload X509 configuration category: Config X509.