Skip to main content

Vega

This Integration is part of the Vega Pack.#

Supported versions

Available on Cortex XSOAR (versions 6.10.0 and later) and Cortex XSIAM.

Vega integration for fetching alerts and incidents from the Vega platform.

This is the default integration for this content pack when configured by the Data Onboarder in Cortex XSIAM.

Configure Vega in Cortex#

ParameterDescriptionRequired
Base URLThe Base URL of the Vega API.True
Access Key IDThe Access Key ID used to authenticate with the Vega API.True
Access KeyThe Access Key used to authenticate with the Vega API.True
Fetch incidentsFalse
Incidents Fetch IntervalTrue
Maximum incidents per fetchThe Maximum number of Vega alerts and incidents to fetch per cycle, combined. Valid range is 1-50. Invalid values default to 50 during fetch.True
Fetch Lookback (minutes)The number of minutes the query window is shifted backwards on each fetch cycle to catch alerts and incidents that were indexed late on the Vega side. Deduplication prevents re- ingestion. Valid range is 1-60.True
Vega Entities to fetchThe Vega entities to fetch as Cortex XSOAR incidents.True
Backfill DaysThe number of days before today to fetch alerts and incidents on the first run. Use 0 for today only. Valid range is 0โ€“365.True
Enable Cortex XSOAR to Vega mirroringWhether to enable Cortex XSOAR to Vega mirroring. When enabled, changes made in Cortex XSOAR investigations are mirrored to Vega for status, verdict, verdict reasoning, severity, and comments. Requires the Vega Outgoing Mapper on this instance. When disabled, Vega to Cortex XSOAR mirroring remains enabled.False
Outgoing fields to mirrorThe investigation fields that are mirrored from Cortex XSOAR to Vega when outgoing mirroring is enabled. If empty, all fields are mirrored. War Room comments are included when Comments is selected. Any custom values entered outside the available options are ignored.False
Alert Severities to fetchThe severities by which to filter alerts. If empty, all severities are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle.False
Alert Statuses to fetchThe statuses by which to filter alerts. If empty, all statuses are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle.False
Alert Verdicts to fetchThe verdicts by which to filter alerts. If empty, all verdicts are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle.False
Has related incidentsThe filter for alerts based on whether they have related incidents. Select Yes to fetch alerts with related incidents, No to fetch alerts without related incidents, or both to fetch all alerts. At least one option must be selected. Filter alerts by whether they have related incidents. Select Yes to fetch alerts with related incidents, No to fetch alerts without related incidents, or both to fetch all alerts. At least one option must be selected.True
Incident Severities to fetchThe severities by which to filter incidents. If empty, all severities are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle. Filter incidents by severity. If empty, all severities are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle.False
Incident Statuses to fetchThe statuses by which to filter incidents. If empty, all statuses are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle. Filter incidents by status. If empty, all statuses are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle.False
Incident Verdicts to fetchThe verdicts by which to filter incidents. If empty, all verdicts are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle. Filter incidents by verdict. If empty, all verdicts are fetched. Any custom values entered outside the available options are ignored and will not affect the fetch cycle.False
Incident typeFalse
Trust any certificate (not secure)False
Use system proxy settingsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

vega-get-alert-events#


Fetch all aggregated alert events for a Vega alert using internal API pagination, then return the requested display page as a markdown table and CustomFields for the Alert Events layout section.

Base Command#

vega-get-alert-events

Input#

Argument NameDescriptionRequired
alert_idThe Vega alert API id (UUID). When omitted, resolves the alert id from the current Vega Alert incident.Optional
limitThe number of alert events to display per page. Also used as the Vega API batch size when fetching all events. Default is 200.Optional
offsetThe pagination offset for alert events. Default is 0.Optional

Context Output#

PathTypeDescription
Vega.AlertEvents.AlertIdStringVega alert ID.
Vega.AlertEvents.TotalNumberTotal number of alert events reported by Vega.
Vega.AlertEvents.OffsetNumberPagination offset used for the current page.
Vega.AlertEvents.LimitNumberPage size used for the current fetch.
Vega.AlertEvents.CountNumberNumber of alert events returned in the current page.
Vega.AlertEvents.HasAlertEventsBooleanWhether the alert returned real alert events instead of aggregated parse-field summary rows.
Vega.AlertEvents.CachedBooleanWhether the response was served from cached incident data.
Vega.AlertEvents.EventsUnknownEnriched alert events for the current page. JSON fields are parsed and fields._raw contents are promoted to top-level keys under fields.
Vega.AlertEvents.CustomFieldsUnknownIncident custom fields to persist for the Alert Events layout section.

vega-set-detections-state#


Set the state for one or more Vega detections.

Base Command#

vega-set-detections-state

Input#

Argument NameDescriptionRequired
idsA comma-separated list of Vega detection IDs to update.Required
stateThe target detection state. Possible values are: ENABLED, DISABLED, TEST_MODE.Required

Context Output#

PathTypeDescription
Vega.DetectionsState.StateStringThe state applied to the detections.
Vega.DetectionsState.IDsStringDetection IDs updated by Vega.
Vega.DetectionsState.CountNumberNumber of detection IDs updated.

vega-update-detections#


Update severity, status, state, and/or tags for one or more Vega detections using the updateDetections GraphQL mutation.

Base Command#

vega-update-detections

Input#

Argument NameDescriptionRequired
detection_idA comma-separated list of Vega detection IDs to update.Required
severityThe target Vega detection severity. Possible values are: LOW, MEDIUM, HIGH, CRITICAL.Optional
stateThe target Vega detection state. Possible values are: ENABLED, DISABLED, TEST_MODE.Optional
tagsA comma-separated list of tags to apply to the Vega detection.Optional

Context Output#

PathTypeDescription
Vega.Detection.IDStringUpdated Vega detection ID.
Vega.Detection.NameStringUpdated Vega detection name.
Vega.Detection.SeverityStringUpdated Vega detection severity.
Vega.Detection.StatusStringUpdated Vega detection status.
Vega.Detection.StateStringUpdated Vega detection state.
Vega.Detection.TagsStringUpdated Vega detection tags.
Vega.Detection.ValidationStatusStringVega validation status for the detection update.

vega-update-alert#


Immediately update Vega alert status, severity, verdict, verdict reasoning, assignees, and/or comment on the Vega platform and sync the open Cortex XSOAR investigation when run from a Vega Alert investigation.

Base Command#

vega-update-alert

Input#

Argument NameDescriptionRequired
alert_idsA comma-separated list of Vega alert IDs to update. Accepts a comma-separated list or repeated values (for example, alert_ids=alert-1,alert-2). Use this to update alerts directly from the war room without opening an investigation. When omitted, the alert ID is resolved from the current Vega Alert investigation. One or more Vega alert IDs to update. Accepts a comma-separated list or repeated values (for example, alert_ids=alert-1,alert-2). Use this to update alerts directly from the war room without opening an investigation. When omitted, the alert ID is resolved from the current Vega Alert investigation.Optional
statusThe target Vega alert status. Possible values are: OPEN, IN PROGRESS, PEER REVIEW, RESOLVED.Optional
verdictThe target Vega alert verdict. Possible values are: MALICIOUS, SUSPICIOUS, BENIGN, INCONCLUSIVE, NA.Optional
severityThe target Vega alert severity. Possible values are: LOW, MEDIUM, HIGH, CRITICAL.Optional
verdict_reasoningThe target Vega alert verdict reasoning.Optional
commentThe comment to add on the Vega alert.Optional
assigneesA comma-separated list of Vega user IDs to assign to the alert.Optional

Context Output#

PathTypeDescription
Vega.Alert.idStringUpdated Vega alert ID.
Vega.Alert.statusStringUpdated Vega alert status.
Vega.Alert.severityStringUpdated Vega alert severity.
Vega.Alert.verdictStringUpdated Vega alert verdict.
Vega.Alert.assigneeStringUpdated Vega alert assignee email, display name, or user ID.

vega-update-incident#


Immediately update Vega incident status, verdict, verdict reasoning, severity, assignee emails, and/or comment on the Vega platform and sync the open Cortex XSOAR investigation when run from a Vega Incident investigation.

Base Command#

vega-update-incident

Input#

Argument NameDescriptionRequired
incident_idsA comma-separated list of Vega incident IDs to update. Accepts a comma-separated list or repeated values (for example, incident_ids=inc-1,inc-2). Use this to update incidents directly from the war room without opening an investigation. When omitted, the incident ID is resolved from the current Vega Incident investigation. One or more Vega incident IDs to update. Accepts a comma-separated list or repeated values (for example, incident_ids=inc-1,inc-2). Use this to update incidents directly from the war room without opening an investigation. When omitted, the incident ID is resolved from the current Vega Incident investigation.Optional
statusThe target Vega incident status. Possible values are: NEW, INVESTIGATING, ON HOLD, EXTERNAL ESCALATION, RESOLVED, REOPENED, REVIEW RECOMMENDED, RESPONSE REQUIRED, UNDER REVIEW.Optional
verdictThe target Vega incident verdict. Possible values are: MALICIOUS, SUSPICIOUS, BENIGN, INCONCLUSIVE, NA.Optional
severityThe target Vega incident severity. Possible values are: LOW, MEDIUM, HIGH, CRITICAL.Optional
verdict_reasoningThe target Vega incident verdict reasoning.Optional
commentThe comment to add on the Vega incident.Optional
assignee_emailsA comma-separated list of email addresses to assign to the Vega incident.Optional

Context Output#

PathTypeDescription
Vega.Incident.idStringUpdated Vega incident ID.
Vega.Incident.statusStringUpdated Vega incident status.
Vega.Incident.verdictStringUpdated Vega incident verdict.
Vega.Incident.severityStringUpdated Vega incident severity.
Vega.Incident.assigneeStringUpdated Vega incident assignee email, display name, or user ID.

get-remote-data#


Gets remote data from a remote Vega alert or incident. Used for debugging incoming mirroring.

Base Command#

get-remote-data

Input#

Argument NameDescriptionRequired
idThe remote Vega alert or incident ID.Required
lastUpdateThe UTC timestamp in seconds (e.g., 1672531200). The incident is only updated if it was modified after the last update time.Optional

Context Output#

There is no context output for this command.

get-modified-remote-data#


Gets Vega alert and incident IDs modified since the last update time. Used for debugging incoming mirroring.

Base Command#

get-modified-remote-data

Input#

Argument NameDescriptionRequired
lastUpdateThe UTC timestamp in seconds (e.g., 1672531200). Returns Vega alert and incident IDs updated since this time.Required

Context Output#

There is no context output for this command.

update-remote-system#


Pushes Cortex XSOAR investigation changes to Vega when outgoing mirroring is enabled.

Base Command#

update-remote-system

Input#

There are no input arguments for this command.

Context Output#

There is no context output for this command.

get-mapping-fields#


Returns the outgoing mirroring fields for Vega Alert and Vega Incident investigations.

Base Command#

get-mapping-fields

Input#

There are no input arguments for this command.

Context Output#

There is no context output for this command.

Incident Mirroring#

You can enable incident mirroring between Cortex XSOAR incidents and Vega corresponding events (available from Cortex XSOAR version 6.0.0). To set up the mirroring:

  1. Enable Fetching incidents in your instance configuration.

Newly fetched incidents will be mirrored in the chosen direction. However, this selection does not affect existing incidents. Important Note: To ensure the mirroring works as expected, mappers are required, both for incoming and outgoing, to map the expected fields in Cortex XSOAR and Vega.