AlienVault USM Anywhere
The AlienVault USM Anywhere connector allows for seamless integration with Swimlane Turbine, enabling automated security event and alarm management.
AlienVault USM Anywhere is a cloud-based security management solution that provides comprehensive threat detection and incident response capabilities. This connector enables Swimlane Turbine users to streamline their security operations by integrating AlienVault's powerful alarm and event management features. Users can add or remove labels for enhanced alarm categorization, retrieve detailed alarm and event information for analysis, and manage security events for efficient incident response. The integration with AlienVault USM Anywhere enhances Swimlane Turbine's automation capabilities, allowing users to quickly and effectively manage security threats within their environment.
Prerequisites
To effectively utilize the AlienVault USM Anywhere connector with Swimlane Turbine, ensure you have the following:
- OAuth 2.0 client credentials for secure authentication, which include:
- URL: The endpoint URL for the AlienVault USM Anywhere API.
- Client ID: Your unique identifier issued when registering with AlienVault.
- Client Secret: A confidential key provided by AlienVault to authenticate your application.
Capabilities
The AlienVault USM Anywhere integration provides the following capabilities:
- Get Event(s)
- Get Alarm(s)
- Get Label IDs
- Add/Delete Label ID for Alarm
Notes
- AlienVault's API uses occured, misspelled from occurred for sort parameter in Get Events and Get Alarms.
Additional Documentation
Configurations
AlienVault Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token_url | ο»Ώ | string | Optional |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Label Alarm
Adds a user-defined label to an alarm in AlienVault USM Anywhere using alarm and label IDs for enhanced categorization.
Endpoint
- URL: api/2.0/alarms/{{alarmid}}/labels/{{labelid}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.alarmid | string | Required | Parameters for the Label Alarm action |
path_parameters.labelid | string | Required | Parameters for the Label Alarm action |
Input Example
{"path_parameters":{"alarmid":"971918fd-a569-548a-5a80-1ffcda2a8365","labelid":"971918fd-a569-548a-5a80-1ffcda2a8365"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK"}
Delete Alarm Label
Removes a specified label from an alarm in AlienVault USM Anywhere, enhancing incident management.
Endpoint
- URL: api/2.0/alarms/{{alarmid}}/labels/{{labelid}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.alarmid | string | Required | Parameters for the Delete Alarm Label action |
path_parameters.labelid | string | Required | Parameters for the Delete Alarm Label action |
Input Example
{"path_parameters":{"alarmid":"971918fd-a569-548a-5a80-1ffcda2a8365","labelid":"971918fd-a569-548a-5a80-1ffcda2a8365"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK"}
Retrieve Alarm
Retrieves detailed information for a specified alarm in AlienVault USM Anywhere using the provided alarm ID.
Endpoint
- URL: api/2.0/alarms/{{alarmid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.alarmid | string | Required | Parameters for the Retrieve Alarm action |
Input Example
{"path_parameters":{"alarmid":"971918fd-a569-548a-5a80-1ffcda2a8365"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
uuid | string | Unique identifier |
has_alarm | boolean | Output field: has_alarm |
needs_enrichment | boolean | Output field: needs_enrichment |
priority | number | Output field: priority |
suppressed | boolean | Output field: suppressed |
events | array | Output field: events |
events.uuid | string | Unique identifier |
rule_intent | string | Output field: rule_intent |
app_type | string | Type of the resource |
source_username | string | Name of the resource |
security_group_id | string | Unique identifier |
destination_name | string | Name of the resource |
timestamp_occured | string | Output field: timestamp_occured |
authentication_type | string | Type of the resource |
event_type | string | Type of the resource |
rule_method | string | HTTP method to use |
priority_label | string | Output field: priority_label |
app_id | string | Unique identifier |
source_name | string | Name of the resource |
timestamp_received | string | Output field: timestamp_received |
rule_strategy | string | Output field: rule_strategy |
request_user_agent | string | Output field: request_user_agent |
rule_id | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK","json_body":{"uuid":"971918fd-a569-548a-5a80-1ffcda2a8365","has_alarm":false,"needs_enrichment":true,"priorit...
Retrieve Alarms
Retrieves a detailed list of alarms from AlienVault USM Anywhere, detailing severity, status, and associated rule names.
Endpoint
- URL: api/2.0/alarms
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | Parameters for the Retrieve Alarms action |
parameters.size | number | Optional | Parameters for the Retrieve Alarms action |
parameters.sort | string | Optional | Parameters for the Retrieve Alarms action |
parameters.status | array | Optional | Parameters for the Retrieve Alarms action |
parameters.suppressed | boolean | Optional | Parameters for the Retrieve Alarms action |
parameters.rule_intent | string | Optional | Parameters for the Retrieve Alarms action |
parameters.rule_method | string | Optional | Parameters for the Retrieve Alarms action |
parameters.rule_strategy | string | Optional | Parameters for the Retrieve Alarms action |
parameters.priority_label | array | Optional | Parameters for the Retrieve Alarms action |
parameters.alarm_sensor_sources | string | Optional | Parameters for the Retrieve Alarms action |
parameters.timestamp_occured_gte | number | Optional | Parameters for the Retrieve Alarms action |
parameters.timestamp_occured_lte | number | Optional | Parameters for the Retrieve Alarms action |
Input Example
{"parameters":{"page":1,"size":50,"sort":"timestamp_occured,asc","status":["open"],"suppressed":true,"rule_intent":"Environmental Awareness","rule_method":"AWS EC2 Security Group Modified","rule_strategy":"Network Access Control Modification","priority_label":["medium"],"alarm_sensor_sources":"308ba880-2518-44bb-9ada-07b158d11713","timestamp_occured_gte":1517933139670,"timestamp_occured_lte":1517933149670}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
_links | object | Output field: _links |
_links.first | object | Output field: _links.first |
_links.first.href | string | Output field: _links.first.href |
_links.first.templated | boolean | Output field: _links.first.templated |
_links.self | object | Output field: _links.self |
_links.self.href | string | Output field: _links.self.href |
_links.self.templated | boolean | Output field: _links.self.templated |
_links.next | object | Output field: _links.next |
_links.next.href | string | Output field: _links.next.href |
_links.next.templated | boolean | Output field: _links.next.templated |
_links.last | object | Output field: _links.last |
_links.last.href | string | Output field: _links.last.href |
_links.last.templated | boolean | Output field: _links.last.templated |
_embedded | object | Output field: _embedded |
_embedded.alarms | array | Output field: _embedded.alarms |
_embedded.alarms.uuid | string | Unique identifier |
_embedded.alarms.has_alarm | boolean | Output field: _embedded.alarms.has_alarm |
_embedded.alarms.needs_enrichment | boolean | Output field: _embedded.alarms.needs_enrichment |
_embedded.alarms.priority | number | Output field: _embedded.alarms.priority |
_embedded.alarms.suppressed | boolean | Output field: _embedded.alarms.suppressed |
_embedded.alarms.destinations | array | Output field: _embedded.alarms.destinations |
_embedded.alarms.destinations.file_name | string | Name of the resource |
_embedded.alarms.destinations.file | string | Output field: _embedded.alarms.destinations.file |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK","json_body":{"_links":{"first":{},"self":{},"next":{},"last":{}},"_embedded":{"alarms":[]},"page":{"size":20,...
Retrieve Event
Retrieve detailed information for a specific event in AlienVault USM Anywhere using the event ID.
Endpoint
- URL: api/2.0/events/{{eventid}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.eventid | string | Required | Parameters for the Retrieve Event action |
Input Example
{"path_parameters":{"eventid":"39a6918f-33f2-ec9b-0fcc-42bb90f10a1f"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
uuid | string | Unique identifier |
account_name | string | Name of the resource |
plugin_device_type | string | Type of the resource |
destination_canonical | string | Output field: destination_canonical |
destination_name | string | Name of the resource |
has_alarm | boolean | Output field: has_alarm |
request_user_agent | string | Output field: request_user_agent |
packet_type | string | Type of the resource |
source_canonical | string | Output field: source_canonical |
event_name | string | Name of the resource |
timestamp_occured | string | Output field: timestamp_occured |
source_service_name | string | Name of the resource |
event_type | string | Type of the resource |
app_name | string | Name of the resource |
timestamp_received | string | Output field: timestamp_received |
destination_hostname | string | Name of the resource |
source_infrastructure_name | string | Name of the resource |
plugin | string | Output field: plugin |
app_type | string | Type of the resource |
authentication_type | string | Type of the resource |
access_control_outcome | string | Output field: access_control_outcome |
suppressed | string | Output field: suppressed |
plugin_device | string | Output field: plugin_device |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK","json_body":{"uuid":"39a6918f-33f2-ec9b-0fcc-42bb90f10a1f","account_name":"generic-account","plugin_device_ty...
Retrieve Events
Fetches a list of security events from AlienVault USM Anywhere for analysis or reporting.
Endpoint
- URL: api/2.0/events
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.page | number | Optional | Parameters for the Retrieve Events action |
parameters.size | number | Optional | Parameters for the Retrieve Events action |
parameters.sort | string | Optional | Parameters for the Retrieve Events action |
parameters.account_name | string | Optional | Parameters for the Retrieve Events action |
parameters.suppressed | boolean | Optional | Parameters for the Retrieve Events action |
parameters.plugin | string | Optional | Parameters for the Retrieve Events action |
parameters.event_name | string | Optional | Parameters for the Retrieve Events action |
parameters.source_name | string | Optional | Parameters for the Retrieve Events action |
parameters.sensor_uuid | string | Optional | Parameters for the Retrieve Events action |
parameters.source_username | string | Optional | Parameters for the Retrieve Events action |
parameters.timestamp_occured_gte | number | Optional | Parameters for the Retrieve Events action |
parameters.timestamp_occured_lte | number | Optional | Parameters for the Retrieve Events action |
Input Example
{"parameters":{"page":1,"size":50,"sort":"timestamp_occured,asc","account_name":"account","suppressed":true,"plugin":"plugin","event_name":"name","source_name":"name","sensor_uuid":"308ba880-2518-44bb-9ada-07b158d11713","source_username":"[email protected]","timestamp_occured_gte":1517933139670,"timestamp_occured_lte":1517933149670}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
_links | object | Output field: _links |
_links.first | object | Output field: _links.first |
_links.first.href | string | Output field: _links.first.href |
_links.first.templated | boolean | Output field: _links.first.templated |
_links.self | object | Output field: _links.self |
_links.self.href | string | Output field: _links.self.href |
_links.self.templated | boolean | Output field: _links.self.templated |
_links.next | object | Output field: _links.next |
_links.next.href | string | Output field: _links.next.href |
_links.next.templated | boolean | Output field: _links.next.templated |
_links.last | object | Output field: _links.last |
_links.last.href | string | Output field: _links.last.href |
_links.last.templated | boolean | Output field: _links.last.templated |
_embedded | object | Output field: _embedded |
_embedded.events | string | Output field: _embedded.events |
page | object | Output field: page |
page.size | number | Output field: page.size |
page.totalElements | number | Output field: page.totalElements |
page.totalPages | number | Output field: page.totalPages |
page.number | number | Output field: page.number |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK","json_body":{"_links":{"first":{},"self":{},"next":{},"last":{}},"_embedded":{"events":"... content omitted f...
Retrieve Alarm Labels
Retrieves labels associated with a specific alarm in AlienVault USM Anywhere using the alarm ID.
Endpoint
- URL: api/2.0/alarms/{{alarmid}}/labels
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.alarmid | string | Required | Parameters for the Retrieve Alarm Labels action |
Input Example
{"path_parameters":{"alarmid":"971918fd-a569-548a-5a80-1ffcda2a8365"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
alarm_labels | array | Output field: alarm_labels |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","client-request-id":"8beed643-f868-4fd0-9e15-e0db4c50383e","x-ms-ags-diagnostic":"","Date":"Tue, 27 Dec 2022 21:12:51 GMT"},"reason":"OK","json_body":{"alarm_labels":["971918fd-a569-548a-5a80-1ffcda2a8365"]}}
Response Headers
Header | Description | Example |
|---|---|---|
client-request-id | HTTP response header: client-request-id | 8beed643-f868-4fd0-9e15-e0db4c50383e |
Content-Encoding | HTTP response header: Content-Encoding | gzip |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Tue, 27 Dec 2022 21:12:51 GMT |
request-id | HTTP response header: request-id | 8beed643-f868-4fd0-9e15-e0db4c50383e |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000 |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding |
x-ms-ags-diagnostic | HTTP response header: x-ms-ags-diagnostic | ο»Ώ |