category: Analytics & SIEM provider: Exabeam sectionorder: - Connect - Collect commonfields: id: Exabeam version: -1 configuration: - display: Server URL (e.g https://100.24.16.156:8484) name: url required: true type: 0 section: Connect - display: Username name: credentials type: 9 required: false section: Connect - additionalinfo: Cluster Authentication Token display: Username displaypassword: API Token name: api_token type: 9 hiddenusername: true required: false section: Connect - defaultvalue: "generic,abnormalAuth,accountManipulation,accountTampering,ueba,bruteForce,compromisedCredentials, cryptomining,dataAccessAbuse,dataExfiltration,dlp,departedEmployee,dataDestruction,evasion,lateralMovement,alertTriage, malware,phishing,privilegeAbuse,physicalSecurity,privilegeEscalation,privilegedActivity,ransomware,workforceProtection" display: Exabeam Incident Type name: incident_type options: - generic - abnormalAuth - accountManipulation - accountTampering - ueba - bruteForce - compromisedCredentials - cryptomining - dataAccessAbuse - dataExfiltration - dlp - departedEmployee - dataDestruction - evasion - lateralMovement - alertTriage - malware - phishing - privilegeAbuse - physicalSecurity - privilegeEscalation - privilegedActivity - ransomware - workforceProtection type: 16 required: false section: Collect advanced: true - defaultvalue: low,medium,high,critical display: Priority name: priority options: - low - medium - high - critical type: 16 required: false section: Collect advanced: true - defaultvalue: closed,closedFalsePositive,inprogress,new,pending,resolved display: Status section: Connect name: status options: - closed - closedFalsePositive - inprogress - new - pending - resolved type: 16 required: false - display: Fetch incidents name: isFetch type: 8 required: false section: Collect advanced: true - defaultvalue: '50' display: Max incidents per fetch name: max_fetch type: 0 required: false section: Collect - defaultvalue: 3 days display: First fetch timestamp (