Skip to main content

Duo Event Collector

This Integration is part of the DUO Admin Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.8.0 and later.

Log collecting for AUDIT events using the Duo API https://duo.com/docs/adminapi#logs.

Configure Duo Event Collector on Cortex XSIAM#

  1. Navigate to Settings > Configurations > Automation & Feed Integrations.
  2. Search for Duo Event Collector.
  3. Click Add instance to create and configure a new integration instance.
ParameterDescriptionRequired
Server HostDuo API host (api-XXXXXXXX.duosecurity.com).True
First fetch from API timeThe time to fetch from for the first run.True
Integration keyAPI integration key.True
Secret keyAPI secret key.True
XSIAM request limitThe maximum number of results to get from the API and to add to XSIAM.True
Request retriesThe number of retries to perform in the API. (This is necessary because if there are too many retries, the API will return a "too many requests 429" error).False
The vendor corresponding to the integration that originated the eventsProduct name of the product to name the dataset after.False
The product corresponding to the integration that originated the eventsVendor name of the product to name the dataset after.False
  1. Click Test to validate the URLs, tokens, and connection.