Skip to main content

Zero Networks Segment

This Integration is part of the Zero Networks Segment Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

This is the Zero Networks event collector integration for Cortex XSIAM.

Configure Zero Networks Segment Event Collector on Cortex XSIAM#

  1. Navigate to Settings > Configurations > Data Collection > Automation & Feed Integrations.

  2. Search for Zero Networks Segment Event Collector.

  3. Click Add instance to create and configure a new integration instance.

    ParameterDescriptionRequired
    Server URLTrue
    API KeyThe API key to use for connection.True
    Fetch network eventsFalse
    Network Activity FiltersUse filters to reduce the amount of events.False
    Maximum audit events to fetchMaximum number of audit events per fetch. The default value is 10000.False
    Maximum network activities events to fetchMaximum number of network activities events per fetch. The default value is 2000.False
    Trust any certificate (not secure)False
    Use system proxy settingsFalse
  4. Click Test to validate the URLs, token, and connection.

Commands#

You can execute these commands from the Cortex XSIAM CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

zero-networks-segment-get-events#


Gets events from Zero Networks Segment.

Base Command#

zero-networks-segment-get-events

Input#

Argument NameDescriptionRequired
should_push_eventsIf true, the command will create events, otherwise it will only display them. Warning: Using this argument may lead to duplicate events. Possible values are: true, false. Default is false.Required
from_dateDate from which to get events.Optional

Context Output#

There is no context output for this command.

Command Example#

!zero-networks-segment-get-events from_date="2024-08-29T12:00:15.000Z"

Human Readable Output#

Audit Events#

timestampauditTypedestinationEntitiesListdetailsenforcementSource
17249282224791{"id": "fake_id"}{"rule":"fake_rule", "id":"fake_id"}1

Network Activities Events#

timestampprotocolstatetrafficTypedstsrc
1724924207581621{"assetId":"fake_dst", "ip":"1.2.3.4"}{"assetId":"fake_src", "ip":"1.1.1.1"}