Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Can this pull Alerts? #61

Open
21020620 opened this issue Mar 4, 2025 · 0 comments
Open

Can this pull Alerts? #61

21020620 opened this issue Mar 4, 2025 · 0 comments

Comments

@21020620
Copy link

21020620 commented Mar 4, 2025

Hi team,
This is just a minor questions, mainly because I am not so sure about what this repo does. However, I am using Trellix and I have a main activity feed where I can see the alerts from all the hosts I manage.
I wonder if I can use this code to pull alerts, and if it can, I would like to send it to Splunk

So I used the samples.splunk argument, and I did uncomment the code part for the any_case_event function.
Butsince I ran the command:

mvision-edr-activity-feed --url https://api.soc.ap-south-1.trellix.com/ --client_id YOUR_CLIENT_ID --client_secret YOUR_CLIENT_SECRET --module samples.splunk --loglevel=debug

I have never received anything, all were empty brackets Received payloads: [], just like the example image in the repo's README file.

I think I have mistaken the command, can someone help with this question please!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant