You can implement a long running integration as a SIEM connector using a webhook.
Procedure
-
Generate and save an access token. For more information, see Creating an Access Token.
-
Create a Commvault Security IQ instance at XSOAR as follows. For more information, see Commvault Security IQ.
-
Specify Commvault API Token.
-
Specify Commvault Webservice URL.
-
Enable Long Running Instance.
-
In Port Mapping, enter a valid available port number.
-
Select Forwarding Rule as Webhook.
-
-
Configure the webhook. For more information, see Generic Webhook.
The webhook URL will be returned in the following format: <CORTEX-XSOAR-URL>/instance/execute/<INTEGRATION-INSTANCE-NAME>.
For example, if the XSOAR hostname is myxsoar.company.com and the Commvault Security IQ instance name is commvault_security_iq, then the webhook URL will be: https://myxsoar.company.com/instance/execute/commvault_security_iq.
-
Configure the webhook as a SIEM connector using the webhook URL created in Step 3, above. For more information, see Adding an SIEM Connector for a Webhook.