Configure the RBVM Data Import Connector to Import RBVM Events
7 min
you can synchronize data to from rbvm, based on filter criteria configured in the rbvm connector settings with use of open data protocol (odata) calls, data is imported directly from rbvm, ensuring updated information is always available this integration also removes the requirement to edit scripts, and the limitation on importing records into the connector configuration ui feature enables you to easily set up a connection, set filter criteria for the data, and set schedules to run the connector and import from rbvm once the data is pulled from rbvm, based on the filter criteria, security events and cis are created if the event severity and risk score of the security event is greater than or equal to 9 (the default value), security incidents are created prerequisites to enable connection between and the rbvm client, your tenant configuration database (db) needs to be configured to permit the connection, which must be setup by please provide getting help docid\ xmvzlfcwdkupkfflhopic with the following information when requesting setup rbvm platform id rbvm client id rbvm api key configure the rbvm connector an rbvm connector is provided in the data import connections list if you cannot locate this connector in the list, contact getting help docid\ xmvzlfcwdkupkfflhopic log in as administrator, and open the select tools > integration tools > data import connections click on the rbvm connector entry the connection settings configuration ui opens you do not need to alter the default settings click test connection the result is displayed in a popup window click next to open the filter setting window the window displays pre populated filter settings based on existing configurations you can review and update the default criteria directly you can add new filters from an extended list of filter specific operators, and apply and/or logic to customize how filters are applied available filters define or modify filter criteria to define or modify filter criteria, follow these steps use the drop down lists to select a field (e g , severity), an operator (e g , greater, lesser), and enter a value (e g , 9) to define multiple criteria, click add to include additional filters use logical operators (and/or) to combine filters and refine the data import logic the filters configured here help narrow down the data imported from the rbvm client based on specific conditions example in the example above, a filter is applied to import only those records where the severity is greater than or equal to 9 you can edit, add, or delete filter criteria at any time within the same window click next , and then select a schedule (or schedules) from the list in the schedule manager select one or more schedules, and then click next to move to the next screen to select multiple schedules, hold down the ctrl key, and then select each schedule you can create a new schedule in the schedule entry workspace if required, and then select it from this list to create a new schedule, refer to about the schedule entry and scheduled jobs workspaces docid\ oly9b8ak4f7dbrbymcikf if no schedule is required, click next to move to the next screen if you select to proceed without a schedule, a confirmation dialog is shown, select yes to proceed, or no to cancel publish the connection configuration publish select this option to publish without running the connection configuration if you selected a schedule, the connection runs at the scheduled time and imports any data from rbvm that meets the filter criteria the imported data is automatically turned into security events and security incidents in publish and run now select this option to publish and run the connection configuration now selecting this option immediately imports any data from rbvm that meets the filter criteria the imported data is automatically turned into security events and security incidents in publish and test run select this option to publish and test the connection and import only, no security events or incidents are created when you run the connector, you can check the integration queue to see if the request is queued, running, or has run and completed to do this select integration tools > integration queue verify the rbvm data import when the rbvm connector run has completed, check the event , ci , and security incident workspaces to verify that any imported data is published into new events, ci records, and security incidents verify security events are created and linked to ci business objects to verify security events are created and are linked to ci business objects log on as administrator open the event workspace and search the event workspace for security events a enter security event in the search field b click show all results select a security event in the list and double click to open it select the details tab and note the host id select the ci tab and verify that the same id is shown under asset id verify cis created from rbvm have a security event linked to verify if the cis created from rbvm have a security event linked log on as administrator open the ci workspace filter the ci list to display cis created from rbvm using the rbvm discovered cis saved search a at the top left of the workspace, click the saved search (all) drop down b click all saved searches at the bottom right of the list c select rbvm discovered cis select a ci entry and double click to open it select the events tab and confirm the corresponding security event(s) are listed multiple events may be linked to the same ci record this occurs if multiple events have the same host id verify security incidents are created security incident creation is triggered in accordance with the risksense create security incident business rule triggered action conditional expression parameter, as configured for the frs evt event security event business object the default trigger conditional expression parameter is $(event severity >= 9 && risk score >= 9), therefore security events with event severity and risk score values greater than or equal to '9' create a security incident to change the parameter setting, open the risksense create security incident business rule triggered action and alter the conditional expression parameter as required for more information, refer to creating a triggered action docid\ a5ujt2tbpnhh zdyrll2w to verify security incidents are created log on as administrator open the security incident workspace and check that corresponding new security incidents are created
