Skip to main content

Duo Event Collector

This Integration is part of the DUO Admin Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.8.0 and later.

Collects Auth and Audit events for Duo using the API.

Configure Duo Event Collector on Cortex XSOAR#

  1. Navigate to Settings > Integrations > Servers & Services.

  2. Search for Duo Event Collector.

  3. Click Add instance to create and configure a new integration instance.

    ParameterRequired
    Server HostTrue
    First fetch timestamp (<number> <time unit>, for example, 12 hours, 7 days, 3 months, 1 year)True
    Integration keyTrue
    Secret keyTrue
    XSIAM request limitTrue
    Request retriesFalse
    Use system proxy settingsFalse
  4. Click Test to validate the URLs, token, and connection.

Commands#

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

duo-get-events#


Manual command to fetch events and display them.

Base Command#

duo-get-events

Input#

Argument NameDescriptionRequired
should_push_eventsSet this argument to True in order to create events, otherwise the command will only display them. Possible values are: True, False. Default is False.Required

Context Output#

There is no context output for this command.