Box (v3.3.1)
Manage Box users and collect events.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Default data source
- BoxEventsCollector
- Categories
- Identity and Access Management, IT Services
Incident fields (6)
- Box Source Created By ID
- Box Source Created By Name
- Box Source Owner ID
- Box Source Owner Name
- Box Source Parent ID
- Box Source Parent Name
Integrations (3)
- Box (Deprecated)
- Box v2
- Box Event Collector
Layouts (1)
- Box Incident
Modeling rules (1)
- BoxEventCollector
Parsing rules (1)
- BoxEventCollector Parsing Rule
README
Box
<~XSIAM>
This pack includes Cortex XSIAM content.
This pack includes
- Collection of Box event log messages.
- Log Normalization - XDM mapping for key event types.
Supported Event Types
- All event types from ./2.0/events API call.
Time Zone support for XSIAM
For supporting Time Zone parsing, time should be set to UTC +0000 Product documentation:
- Sign into your Box account.
- Click your initials in the top-right corner to open the Account Menu.
- Click Account Settings.
- The Account tab should open by default. Locate the General Options section.
- Select your preferred timezone from the pulldown menu under Time Zone.
- Click Save Changes in the top right to save your settings.
Enabling Box Event Collector
To configure the Box Event Collector to receive log messages:
- Make sure you have the Box pack installed on your Cortex XSIAM tenant.
- Go to Settings → Configurations → Automation & Feed Integrations.
- In the search bar, type Box and click + Add instance.
- Follow the integration steps to send logs from Box to your Cortex XSIAM tenant.
</~XSIAM>