Skip to main content

Zero Networks Segment

This Integration is part of the Zero Networks Segment Pack.#

Supported versions

Supported Cortex XSOAR versions: 6.10.0 and later.

This is the Zero Networks event collector integration for Cortex XSIAM.

Configure Zero Networks Segment Event Collector in Cortex#

ParameterDescriptionRequired
Server URLTrue
API KeyThe API key to use for connection.True
Fetch network eventsFalse
Network Activity FiltersUse filters to reduce the amount of events.False
Maximum audit events to fetchMaximum number of audit events per fetch. The default value is 10000.False
Maximum network activities events to fetchMaximum number of network activities events per fetch. The default value is 2000.False
Trust any certificate (not secure)False
Use system proxy settingsFalse

Commands#

You can execute these commands from the CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

zero-networks-segment-get-events#


Gets events from Zero Networks Segment.

Base Command#

zero-networks-segment-get-events

Input#

Argument NameDescriptionRequired
should_push_eventsIf true, the command will create events, otherwise it will only display them. Warning: Using this argument may lead to duplicate events. Possible values are: true, false. Default is false.Required
from_dateDate from which to get events.Optional

Context Output#

There is no context output for this command.

Command Example#

!zero-networks-segment-get-events from_date="2024-08-29T12:00:15.000Z"

Human Readable Output#

Audit Events#

timestampauditTypedestinationEntitiesListdetailsenforcementSource
17249282224791{"id": "fake_id"}{"rule":"fake_rule", "id":"fake_id"}1

Network Activities Events#

timestampprotocolstatetrafficTypedstsrc
1724924207581621{"assetId":"fake_dst", "ip":"1.2.3.4"}{"assetId":"fake_src", "ip":"1.1.1.1"}