SpyCloud Watachlist data - SpyCloud Enterprise

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This Playbook will run daily, gets the watchlist data from SpyCloud API and saved it into the custom logs.

Attribute Value
Type Playbook
Solution SpyCloud Enterprise Protection
Source View on GitHub

Logic App Connectors

This playbook uses 3 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azureloganalyticsdatacollector Managed 1 2
spycloud-enterprise-connector Managed 0 2
SpyCloud-Enterprise-Protection Custom 1 0
Action parameters (URLs, paths, function IDs)

azureloganalyticsdatacollector (Managed)

Action Method Endpoint Other
Save_Modified_Records_to_Custom_Logs_Table post /api/logs
Save_New_Records_to_Custom_Logs_Table post /api/logs

spycloud-enterprise-connector (Managed)

Action Method Endpoint Other
Get_Breach_Data_for_Entire_Watchlist_2 get /breach/data/watchlist
Get_Breach_Data_for_Entire_Watchlist get /breach/data/watchlist

Additional Documentation

📄 Source: SpyCloud-Monitor-Watchlist-Data/readme.md

SpyCloud Enterprise Monitor Watchlist Data Playbook

SpyCloud Enterprise

Table of Contents

  1. Overview
  2. Prerequisites
  3. Deployment
  4. Post Deployment Steps

Overview

This playbook gets triggered on a daily basis and performs the following actions:

Prerequisites

Deployment Instructions

Deploy to Azure Deploy to Azure Gov

Post-Deployment Instructions

Provide Custom Log Table Name

Recurrence Trigger Instructions

Authorize connections

Once deployment is complete, you will need to authorize each connection:


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to SpyCloud Enterprise Protection