Coder Social home page Coder Social logo

mimecast-apis-splunk-ta's Introduction

Mimecast Campaigns

Overview

This TA collects data from Mimecast Awareness Training API, specifically the "Get Campaigns" and "Get User Data" endpoints.

Releases

Version 2.0.0 was released on 19 July 2024. It is now built on top of Splunk Add-on Builder.

Requirements and Configuration

To configure an input after installing this app, go to the app's Inputs landing page and hit Create New Input. You will need to supply the the following:

  • Grid or Tenant API URL
  • Access Key
  • Secret Key
  • App Id
  • App Key
  • Launch Date
    • This is your organization's chosen start of Phishing Simulation Campaign
    • Multiple phishing simulation emails may be sent over the course of few days and this date should be the very start of the campaign
  • End Date
    • This is the desired end date of the Phishing Simulation Campaign
    • Some users may still action (e.g. Click, Report) on simulated phishing emails but your may not want these data to avoid changes in already-established score or result
  • Include All User Data
    • A checkbox that will ignore the Campaign End Date
    • When this is checked, users who actioned on simulated phishing emails will still be ingested but will have a field isOutsideCampaignPeriod with a value of True

The recommended interval for an inputs stanza is once per day. You may immediately turn off the collection after just one successful collection.

Troubleshooting

See the collection's logs by querying internal logs, such as:

index=_internal sourcetype=tamimecastcampaigns:log 
| transaction pid source

Disclaimer

The author of this add-on is not employed by Mimecast. This was built out of necessity. The main Splunk TA built by Mimecast is found here: https://splunkbase.splunk.com/app/4075/

For more details about the API, visit https://integrations.mimecast.com/documentation/endpoint-reference/awareness-training/

Support

If you want to translate the logs collected by this TA into a dashboard summary, you may reach out to my personal email [email protected]. My rate is one pint of IPA per hour.

mimecast-apis-splunk-ta's People

Contributors

morethanyell avatar

Watchers

Kostas Georgiou avatar  avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.