Skip to main content

Arcanna.AI

Supported versions

Supported Cortex XSOAR versions: 5.5.0 and later.

Arcanna integration for using the power of AI in SOC This integration was integrated and tested with version 1.0 and above of Arcanna.AI

Configure Arcanna.AI on Cortex XSOAR#

  1. Navigate to Settings > Integrations > Servers & Services.

  2. Search for Arcanna.AI.

  3. Click Add instance to create and configure a new integration instance.

    ParameterDescriptionRequired
    Server URLURL of Arcanna APITrue
    API KeyApi Key for Arcanna APITrue
    Trust any certificate (not secure)False
    Use system proxy settingsFalse
    Default Arcanna Job IdDefault Arcanna Job IdFalse
  4. Click Test to validate the URLs, token, and connection.

Commands#

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

arcanna-get-jobs#


Get jobs list

Base Command#

arcanna-get-jobs

Input#

There are no input arguments for this command.

Context Output#

PathTypeDescription
Arcanna.Jobs.job_idIntArcanna Job id
Arcanna.Jobs.data_typeStringArcanna Job type
Arcanna.Jobs.titleStringArcanna Job title
Arcanna.Jobs.statusStringArcanna job status

Command Example#

!arcanna-get-jobs

Context Example#

{
"Arcanna": {
"Jobs": [
{
"data_type": "es",
"job_id": 1101,
"status": "IDLE",
"title": "cortex"
}
]
}
}

Human Readable Output#

Arcanna Jobs#

job_idtitledata_typestatus
1101cortexesIDLE

arcanna-send-event#


Sends a raw event to Arcanna

Base Command#

arcanna-send-event

Input#

Argument NameDescriptionRequired
job_idarcanna running job_id.Optional
event_jsonjson event for arcanna to inference.Required
titleevent title.Required
severityevent severity.Optional

Context Output#

PathTypeDescription
Arcanna.Event.event_idNumberArcanna event id
Arcanna.Event.statusStringArcanna ingestion status
Arcanna.Event.ingest_timestampdateArcanna ingestion timestamp
Arcanna.Event.error_messageStringArcanna error message if any

arcanna-get-event-status#


Retrieves Arcanna Inference result

Base Command#

arcanna-get-event-status

Input#

Argument NameDescriptionRequired
job_idArcanna Job Id.Optional
event_idArcanna generated unique event id.Required

Context Output#

PathTypeDescription
Arcanna.Event.event_idStringArcanna event id
Arcanna.Event.ingest_timestampStringArcanna ingestion timestamp
Arcanna.Event.confidence_levelNumberArcanna ML confidence_level
Arcanna.Event.resultStringArcanna event result
Arcanna.Event.is_duplicatedbooleanArcanna signalling if event is duplicated by another alert
Arcanna.Event.error_messageStringArcanna error message if any
Arcanna.Event.statusStringarcanna event status

Command Example#

!arcanna-get-event-status job_id="1102" event_id="11021484171024"

Context Example#

{
"Arcanna": {
"Event": {
"confidence_level": 0.9999940395355225,
"error_message": null,
"event_id": "11021484171024",
"ingest_timestamp": "2021-07-02T10:16:12.148417",
"is_duplicated": false,
"result": "drop_alert",
"status": "OK"
}
}
}

Human Readable Output#

{'event_id': '11021484171024', 'ingest_timestamp': '2021-07-02T10:16:12.148417', 'status': 'OK', 'confidence_level': 0.9999940395355225, 'result': 'drop_alert', 'is_duplicated': False, 'error_message': None}#

arcanna-get-default-job-id#


Retrieves Arcanna Default Job id

Base Command#

arcanna-get-default-job-id

Input#

There are no input arguments for this command.

Context Output#

PathTypeDescription
Arcanna.Default_Job_IdStringArcanna Default Job id

Command Example#

!arcanna-get-default-job-id

Context Example#

{
"Arcanna": {
"Default_Job_Id": "1102"
}
}

Human Readable Output#

1102#

arcanna-set-default-job-id#


Sets Arcanna Default Job id

Base Command#

arcanna-set-default-job-id

Input#

Argument NameDescriptionRequired
job_idjob_id.Required

Context Output#

PathTypeDescription
Arcanna.Default_Job_IdUnknownArcanna default job id

Command Example#

!arcanna-set-default-job-id job_id=1102

Context Example#

{
"Arcanna": {
"Default_Job_Id": "1102"
}
}

Human Readable Output#

1102#