category: Endpoint sectionorder: - Connect - Collect provider: Broadcom commonfields: id: Carbon Black Endpoint Standard v3 version: -1 configuration: - name: url defaultvalue: https://defense.conferdeploy.net/ display: URL required: true type: 0 section: Connect - name: organization_key display: Organization Key type: 0 required: true section: Connect - name: custom_credentials display: Custom Api Key type: 9 required: false additionalinfo: Also required for fetch section: Connect - name: live_response_credentials display: Api Key (Api/Live Response key) type: 9 required: false section: Connect - name: incidentType display: Incident type type: 13 required: false section: Collect - display: Incidents Fetch Interval name: incidentFetchInterval defaultvalue: '1' required: false type: 19 section: Collect advanced: true - name: isFetch display: Fetch incidents type: 8 required: false section: Collect - name: insecure display: Trust any certificate (not secure) type: 8 required: false section: Connect - name: proxy display: Use system proxy settings type: 8 required: false section: Connect - name: type display: The type of the alert defaultvalue: all options: - cbanalytics - containerruntime - devicecontrol - hostnasedfirewall - intrusiondetectionsystem - watchlist - all type: 15 required: false additionalinfo: Type of alert to be fetched. section: Collect - name: device_id display: Device ID type: 0 required: false additionalinfo: The alerts related to a specific device, according to the device ID. section: Collect - name: policy_id display: Policy ID type: 0 required: false additionalinfo: The alerts related to a specific policy, according to the policy ID. section: Collect - name: device_username display: Device username type: 0 required: false additionalinfo: The alerts related to a specific device, according to the device username. section: Collect - name: min_severity display: Minimum severity options: - '1' - '2' - '3' - '4' - '5' - '6' - '7' - '8' - '9' - '10' type: 15 required: false additionalinfo: The minimum severity of the alerts to be fetched. section: Collect - name: query display: Query type: 0 required: false additionalinfo: Query in Lucene syntax and/or value searches. If defined, the other fetch incidents parameters should be left blank. section: Collect - name: first_fetch display: First fetch timestamp (