Incoming feed - Exabeam Event Feed#
This article describes how to configure incoming feeds for a particular feed source. To see how to configure incoming feeds in general, see Create and configure incoming feeds.
Exabeam Event Feed
Exabeam Event JSON
Uses the Exabeam Event Search API to retrieve Exabeam events that match a given search query and ingests them as Sighting entities.
Exabeam instance URL
Exabeam user account with permissions to access:
Event search API
For that user account:
Exabeam client key/ID
Exabeam client secret
Configure the incoming feed#
Create or edit an incoming feed.
(Recommended) Exclude unstructured data. Select Advanced options > Skip extraction of observables from unstructured text.
Under Transport and content, fill out these fields:
Required fields are marked with an asterisk (*).
Select Exabeam Event Feed from the drop-down menu.
Select Exabeam Event JSON from the drop-down menu.
Set this to the URL for your Exabeam instance.
Enter your Exabeam client key/ID.
Enter your Exabeam client secret.
Enter an Exabeam search query.
See the Exabeam documentation.
Event Limit *
Enter the maximum number of events to retrieve from Exabeam. This is the maximum number of events that this feed will retrieve from Exabeam each time it runs.
Limitation: Each time this feed runs, it retrieves the most recent Event limit number of Exabeam events since Start ingestion from. If you expect to ingest more events for a given Start ingestion from date and time, running the feed again without changing the Event limit will not retrieve the “next” chunk of events.
For example, for the period where Start ingestion from is
2023-11-01T00:00:00and we run the feed now (
2023-11-25T00:00:00), and Event limit is
3000, running the feed repeatedly will ingest (and deduplicate) the same 3000 events for the same Filter value (search query).
In this example, new events are ingested in 3 cases (provided there are available Exabeam event):
New events have been triggered since the last time the feed was run (
The Start ingestion from is changed to an earlier timestamp.
Event limit is increased.
Store your changes by selecting Save.
Exabeam events are ingested as Sighting entities with:
Titles formatted as
Exabeam event #<event.id>. Example:
Exabeam Event #75d4c995-39f4-4cd8-bfba-9f72f141c625.
IoCs identified by event are ingested as related observables.