Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Feature

Details

Allow parallel downloading (multipod)

  • not allowed

Running environments

  • collector server

Populated Devo events

  • table

Flattening preprocessing

  • no

Data sources

Data source

Description

API endpoint

Collector service name

Devo table

Available from release

Alert Summary

Gets a list of advanced threat alerts in summary format.

POST <https://<etp_instance_addr>>/api/v1/alerts

alerts_summary

mail.trellix.etp.alert_summary

v1.0.0

Email Trace

This retrieves email trace information as per the attributes

POST <https://<etp_instance_addr>>/api/v1/messages/trace

email_trace

mail.trellix.etp.email_trace

v1.0.0

User Activity

Searches the user activity for the Admin Users of the client

POST <https://<etp_instance_addr>>/api/v1/users/activitylogs/search

user_activity_search

mail.trellix.etp.user_actiivity_search

v1.0.0

Statistics

Users can view the statistics of emails on the ETP Portal.

POST <https://<etp_instance_addr>>/api/v1/stats

statistics

mail.trellix.etp.statistic

v1.0.0

For more information on how the events are parsed, visit our page.

Flattening preprocessing

Data source

Collector service

Optional

Flattening details

Alert Summary

alerts_summary

yes

Flattening not required.

Email Trace

email_trace

yes

Flattening not required.

User Activity

user_activity_search

yes

Flattening not required.

Statistics

statistics

yes

Flattening not required.

Minimum configuration required for basic pulling

...