Box (v3.3.1)

Manage Box users and collect events.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Default data source
BoxEventsCollector
Categories
Identity and Access Management, IT Services

Incident fields (6)

Integrations (3)

Layouts (1)

Modeling rules (1)

Parsing rules (1)

README

Box

<~XSIAM>

This pack includes Cortex XSIAM content.

This pack includes

Supported Event Types

Time Zone support for XSIAM

For supporting Time Zone parsing, time should be set to UTC +0000 Product documentation:

  1. Sign into your Box account.
  2. Click your initials in the top-right corner to open the Account Menu.
  3. Click Account Settings.
  4. The Account tab should open by default. Locate the General Options section.
  5. Select your preferred timezone from the pulldown menu under Time Zone.
  6. Click Save Changes in the top right to save your settings.

Enabling Box Event Collector

To configure the Box Event Collector to receive log messages:

  1. Make sure you have the Box pack installed on your Cortex XSIAM tenant.
  2. Go to SettingsConfigurationsAutomation & Feed Integrations.
  3. In the search bar, type Box and click + Add instance.
  4. Follow the integration steps to send logs from Box to your Cortex XSIAM tenant.

</~XSIAM>