category: Endpoint sectionorder: - Connect - Collect provider: Broadcom commonfields: id: Carbon Black Endpoint Standard version: -1 configuration: - defaultvalue: https://defense.conferdeploy.net/ display: URL name: url required: true type: 0 section: Connect - display: Custom Api Key (using for API version 6) name: custom_credentials type: 9 required: false section: Connect - display: Api Key (Api/Live Response key using for API version 3) name: live_response_credentials type: 9 required: false section: Connect - additionalinfo: The organization unique key. This is required for all use cases (and for fetching incidents) except the policy use cases. display: Organization Key name: organization_key type: 0 required: false section: Connect - display: Incident type name: incidentType type: 13 required: false section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 advanced: true section: Collect - display: Fetch incidents name: isFetch type: 8 required: false section: Collect - display: Trust any certificate (not secure) name: insecure type: 8 required: false section: Connect - display: Use system proxy settings name: proxy type: 8 required: false section: Connect - additionalinfo: Type of alert to be fetched. defaultvalue: all display: The type of the alert name: suffix_url_path options: - all - cbanalytics - devicecontrol type: 15 required: false section: Connect - additionalinfo: Category of alert to be fetched (THREAT, MONITORED). If nothing is selected he is fetching from all categories. display: The category of the alert. name: category options: - THREAT - MONITORED type: 16 required: false section: Collect - additionalinfo: The alerts related to a specific device, represented by its ID. display: Device id name: device_id type: 0 required: false section: Collect - additionalinfo: The alerts related to a specific policy, represented by its ID. display: Policy id name: policy_id type: 0 required: false section: Collect - additionalinfo: The alerts related to a specific device, represented by its username. display: Device username name: device_username type: 0 required: false section: Collect - additionalinfo: The minimum severity of the alerts to be fetched. display: Minimum severity name: min_severity options: - '1' - '2' - '3' - '4' - '5' - '6' - '7' - '8' - '9' - '10' type: 15 required: false section: Collect - additionalinfo: Query in Lucene syntax and/or value searches. If defined, the other fetch incidents parameters should be left blank. display: Query name: query type: 0 required: false section: Collect - defaultvalue: 7 days display: First fetch timestamp (