-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Workday Sign on Event Collector #28832
Merged
Merged
Changes from 53 commits
Commits
Show all changes
67 commits
Select commit
Hold shift + click to select a range
741a47e
Stashin this for a minute or two
amshamah419 ef76c7a
Add more testing, refactor for performance
amshamah419 8bec10e
Add even more testing
amshamah419 3302015
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 b7a6a90
Current status
amshamah419 9003c9f
Code mostly ready for CR
amshamah419 dd6a7f5
Push modeling rules
amshamah419 b8f4fac
Add example event
amshamah419 e47953f
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 2f6cee8
RM Modeling Rules, performance enhancements, lint, and UTs
amshamah419 4fd4fde
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 1a1f834
Merge branch 'master' into workday-signon-event-collector
amshamah419 691936c
Merge remote-tracking branch 'origin/workday-signon-event-collector' …
amshamah419 f7caa8b
Desc, Readme
amshamah419 8f902bf
Changes per CR
amshamah419 9c58297
Update UT to reflect change in lastrun behavior
amshamah419 cabb84b
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 ea318c5
Minor updates Bump pack version
amshamah419 a5e3323
Precommit changes to event generator
amshamah419 d765976
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 2a25e3e
update-modeling-rules
cweltPA e7b3db3
fix-modeling-rules-chema-type-typo
cweltPA 68a2f84
update-known-words-in-pack-ignore
cweltPA 8399c5f
update-known-words-in-pack-ignore
cweltPA 3b27563
fix-modeling-rules-syntax-error
cweltPA 12030a5
Modifications to some UTs
amshamah419 4686c37
Merge remote-tracking branch 'origin/workday-signon-event-collector' …
amshamah419 525e34e
fix-modeling-rules-syntax-error
cweltPA a184ee8
update-release-notes-for-modeling-rules
cweltPA 4070085
migrate-signon-modeling-rules-to-the-existing-directory
cweltPA 8588468
Linting
amshamah419 f4ca2b4
Merge remote-tracking branch 'origin/workday-signon-event-collector' …
amshamah419 802120b
Merge branch 'master' into workday-signon-event-collector
cweltPA cc60608
fix-modeling-rules-constant-issue
cweltPA f7d3c81
refactor-modeling-rules
cweltPA e536269
Merge branch 'master' into workday-signon-event-collector
cweltPA a7a5eb2
remove-duration-modeling
cweltPA 9c4974a
update-release-notes
cweltPA ee0cdd6
update-release-notes
cweltPA 17228e8
update-release-notes
cweltPA 822a14e
Merge branch 'master' into workday-signon-event-collector
cweltPA e085048
refactor-modeling-rules
cweltPA 5237fc8
Merge branch 'master' into workday-signon-event-collector
cweltPA 191615c
whoops
amshamah419 882c143
Merged master into current branch.
ad8116d
Bump pack from version Workday to 1.4.0.
1fef9cf
refactor-modeling-rules
cweltPA 25eba78
Merge branch 'master' into workday-signon-event-collector
cweltPA a3d0cc2
update-docs
cweltPA bb9d55c
Changes per Demo
amshamah419 e615cdd
Merge remote-tracking branch 'origin/workday-signon-event-collector' …
amshamah419 a094813
Apply changes from docs-review
amshamah419 b044a57
Apply suggestions from code review
amshamah419 e3311ca
Apply changes from code review
amshamah419 2ff97a1
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 db60abb
Merge remote-tracking branch 'origin/workday-signon-event-collector' …
amshamah419 0ce923f
Lint fixes
amshamah419 3dc34e7
Lint fix for nested with
amshamah419 01bdeae
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 dd64939
Changes from live testing
amshamah419 0253ee4
Changes from live testing
amshamah419 0ab8090
update-dataset-name-in-modeling-rule
cweltPA 001acc0
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 51768d1
sign_on -> signon
amshamah419 f2f5867
Merge branch 'master' of github.com:demisto/content into workday-sign…
amshamah419 5c0ec31
Merge branch 'master' into workday-signon-event-collector
amshamah419 6622e98
Merge branch 'master' into workday-signon-event-collector
cweltPA File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
49 changes: 49 additions & 0 deletions
49
Packs/Workday/Integrations/WorkdaySignOnEventCollector/README.md
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,49 @@ | ||
Use the Workday Sign On Event Collector integration to get sign on logs from Workday. | ||
This integration was integrated and tested with version v37.0 of Workday Sign On Event Collector. | ||
|
||
## Configure Workday Sign On Event Collector on Cortex XSOAR | ||
|
||
1. Navigate to **Settings** > **Integrations** > **Servers & Services**. | ||
2. Search for Workday Sign On Event Collector. | ||
3. Click **Add instance** to create and configure a new integration instance. | ||
|
||
| **Parameter** | **Description** | **Required** | | ||
---------------------------------------------------| --- | --- | --- | | ||
| Server URL (e.g., https://services1.myworkday.com) | API Endpoint of Workday server. Can be obtained from View API Clients report in Workday application. | True | | ||
| Tenant Name | The name of the Workday Tenant. Can be obtained from View API Clients report in Workday application. | True | | ||
| Username | | True | | ||
| Password | | True | | ||
| Trust any certificate (not secure) | | False | | ||
| Use system proxy settings | | False | | ||
| Max events per fetch | The maximum number of sign on events to retrieve. Large amount of events may cause performance issues. | False | | ||
| Events Fetch Interval | | False | | ||
|
||
4. Click **Test** to validate the URLs, token, and connection. | ||
|
||
## Commands | ||
|
||
You can execute these commands from the Cortex XSIAM CLI, as part of an automation, or in a playbook. | ||
After you successfully execute a command, a DBot message appears in the War Room with the command details. | ||
|
||
### workday-get-sign-on-events | ||
|
||
*** | ||
Returns sign on events extracted from Workday. This command is used for developing/debugging and is to be used with caution, as it can create events, leading to events duplication and exceeding the API request limitation. | ||
|
||
#### Base Command | ||
|
||
`workday-get-sign-on-events` | ||
|
||
#### Input | ||
|
||
| **Argument Name** | **Description** | **Required** | | ||
|--------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------| | ||
| should_push_events | Set this argument to True in order to create events, otherwise the command will only display them. Possible values are: True, False. Default is False. | Required | | ||
| limit | The maximum number of events to return. Default is 1000. | Optional | | ||
| from_date | The date and time of the earliest event. The default timezone is UTC/GMT. The time format is "{yyyy}-{mm}-{dd}T{hh}:{mm}:{ss}Z". Example: "2021-05-18T13:45:14Z" indicates May 18, 2021, 1:45PM UTC. | Optional | | ||
| to_date | The time format is "{yyyy}-{mm}-{dd}T{hh}:{mm}:{ss}Z". Example: "2021-05-18T13:45:14Z" indicates May 18, 2021, 1:45PM UTC. | Optional | | ||
| relative_from_date | The query from date, for example, "5 minutes". Be advised, it is strongly suggested to keep this parameter limited in time. | Optional | | ||
|
||
#### Context Output | ||
|
||
There is no context output for this command. | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
There is outputs I think but since its for developing I think its ok to leave it.