Absolute (v2.0.12)

Absolute is an adaptive endpoint security solution that delivers device security, data security and asset management of endpoints

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Endpoint

Integrations (1)

Modeling rules (1)

Parsing rules (1)

README

Absolute

Absolute enables you to manage and secure your data, devices, and applications with an unbreakable connection to every endpoint. Your sensitive data remains protected, even when accessed from outside your network.

What does this pack do?

Prerequisites

To configure an instance of Absolute, you need to obtain the following information.

Create a Token ID and Secret Key

  1. In the Absolute console, click the + (in the quick access toolbar) > API Token.
  2. On the API Token Management page, click the Create token button. The Create Token dialog box appears.
  3. Enter a Token name and Description.
  4. Click Save (The Token Created dialog box displays your generated token ID).
  5. Download the token ID and secret key or view the secret key.
    Note: If you close this dialog box before downloading or copying the secret key, you cannot retrieve it later.

Download the Token ID and Secret Key

  1. Click Download Token.
  2. Save the .token file.
  3. Use a text editor to open and view the file.
  4. To view the secret key:
    1. Click View Secret Key. The secret key is populated.
    2. Copy both values of the Token ID and Secret key to a text file and save the file.
  5. Click Close.

Notes

Supported Event Types

Absolute Event Collector

To enable the MongoDB Atlas Event Collector, follow these steps:

  1. Go to SettingsConfigurationsAutomation & Feed Integrations.
  2. In the search bar, type Absolute.
  3. At the right-corner, click + Add instance.
  4. Follow the instruction in the prompt window to configure the Absolute Event Collector.