Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Get alert Info using API

    Posted 11-05-2020 10:29
    Hi,

    Has anyone used API/ scripts to pull alerts and its details from MX. If so, how?

    Thanks
    #On-PremisesWAF(formerlySecuresphere)

    ------------------------------
    SC
    ------------------------------


  • 2.  RE: Get alert Info using API

    Posted 11-09-2020 08:00

    @Shantanu Chaurasia

    It could make sense for you to look at the Imperva github page around mx-toolbox​@Brian Anderson also talks about some of this in a webibar he hosted several months back. Found here: GitHub Tools - Imperva API Composer.  

    Does this help? 
    ---------

    The SecureSphere / WAF Gateway  MX-Toolbox is a general purpose repository for custom packages, integrations, and monitoring add-ons for the SecureSphere MX and Gateway appliances.

    1. Alerts to New Relic - Send alerts to New Relic via custom action set
    2. Camo CX-Discover Integration - Process CAMO classification .csv report to create table groups, and convert to json to push to S3
    3. ServiceNow Integration - Alert to incident, change control reconciliation audit enrichment, close-the-loop updating change requests with queries, and vulnerability assessment export to CMDB and vulnerable items in ServiceNow
    4. Export KRP Rules to Dataset - Export KRP rules in the siote tree to .csv and upload to data set
    5. Export WAF Profile Learned Hosts to CSV - Export all learned hosts in web profiles to .csv
    6. Export Table Groups to CSV - Export table groups to .csv
    7. MX WAF Security Policy Sync - Replicate and sync security policies across multiple MXs in AWS
    8. MX and Gateway Performance Monitoring - Output performance data (CPU, counters, network stats, disk, etc) from both MX and Gateway appliances in near real-time simultaneously to new relic, influxdb/grafana, and/or to SIEM via syslog with uniquely indexed json.





    ------------------------------
    Christopher Detzel
    Community Manager
    Imperva
    ------------------------------



  • 3.  RE: Get alert Info using API

    Posted 11-10-2020 10:50
    @Shantanu Chaurasia
    You could use SecureSphere API to pull alert details.
    Ref: https://docs.imperva.com/bundle/v13.6-api-reference-guide/page/69955.htm


    ------------------------------
    John Andra
    ------------------------------



  • 4.  RE: Get alert Info using API

    Posted 11-12-2020 10:06
    Thanks Christopher and John, I will try these.

    ------------------------------
    SC
    ------------------------------