<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending Harmony Endpoint EDR Detections to a SIEM in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Sending-Harmony-Endpoint-EDR-Detections-to-a-SIEM/m-p/163924#M6261</link>
    <description>&lt;P&gt;I've written a Python module for querying Harmony Endpoint detections ('Active Attacks'). The code is here, within a Splunk add-on for ingesting those alerts into Splunk.&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/gf13579/ta_for_cpharmony" target="_blank" rel="noopener"&gt;gf13579/ta_for_cpharmony (github.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Note that the module can be used independently of Splunk - just grab&amp;nbsp;cpharmonylib.py and&amp;nbsp;cpharmony_consts.py.&lt;/P&gt;&lt;P&gt;Also note that this code isn't using the Harmony Connect API (&lt;A href="https://app.swaggerhub.com/apis-docs/Check-Point/harmony-connect-api" target="_blank" rel="noopener"&gt;Build, Collaborate &amp;amp; Integrate APIs | SwaggerHub&lt;/A&gt;) as that doesn't appear to support querying endpoint detections (yet). The module I've written is leveraging the APIs used by the Infinity Portal itself.&lt;/P&gt;&lt;P&gt;This blog post explains how it works in more detail:&amp;nbsp;&lt;A href="https://spinningplates.net/posts/borrowing-apis-from-single-page-apps/" target="_blank" rel="noopener"&gt;Connecting the Unconnectable; Borrowing APIs from Single Page Applications | spinning plates&lt;/A&gt;.&lt;/P&gt;</description>
    <pubDate>Fri, 02 Dec 2022 04:55:34 GMT</pubDate>
    <dc:creator>cp65536</dc:creator>
    <dc:date>2022-12-02T04:55:34Z</dc:date>
    <item>
      <title>Sending Harmony Endpoint EDR Detections to a SIEM</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sending-Harmony-Endpoint-EDR-Detections-to-a-SIEM/m-p/163924#M6261</link>
      <description>&lt;P&gt;I've written a Python module for querying Harmony Endpoint detections ('Active Attacks'). The code is here, within a Splunk add-on for ingesting those alerts into Splunk.&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/gf13579/ta_for_cpharmony" target="_blank" rel="noopener"&gt;gf13579/ta_for_cpharmony (github.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Note that the module can be used independently of Splunk - just grab&amp;nbsp;cpharmonylib.py and&amp;nbsp;cpharmony_consts.py.&lt;/P&gt;&lt;P&gt;Also note that this code isn't using the Harmony Connect API (&lt;A href="https://app.swaggerhub.com/apis-docs/Check-Point/harmony-connect-api" target="_blank" rel="noopener"&gt;Build, Collaborate &amp;amp; Integrate APIs | SwaggerHub&lt;/A&gt;) as that doesn't appear to support querying endpoint detections (yet). The module I've written is leveraging the APIs used by the Infinity Portal itself.&lt;/P&gt;&lt;P&gt;This blog post explains how it works in more detail:&amp;nbsp;&lt;A href="https://spinningplates.net/posts/borrowing-apis-from-single-page-apps/" target="_blank" rel="noopener"&gt;Connecting the Unconnectable; Borrowing APIs from Single Page Applications | spinning plates&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 04:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sending-Harmony-Endpoint-EDR-Detections-to-a-SIEM/m-p/163924#M6261</guid>
      <dc:creator>cp65536</dc:creator>
      <dc:date>2022-12-02T04:55:34Z</dc:date>
    </item>
  </channel>
</rss>

