Skip to main content

Responses are generated using AI and may contain mistakes.

Context ManagementContext Management Administration Guide

REST API Context Tables

tile-stix-taxii.png

The REST API option is designed to streamline the process of creating a new REST API context table. When the context table is onboarded, it processes either user, device, or other attributes that a REST API Context cloud collector has pulled from a source API endpoint.

You can configure REST API Context collectors (separate from log collectors) in In Cloud Collectors service. They facilitate data collection via REST API endpoints from a range of vendors and products. These cloud collectors simplify third-party log ingestion so that you can create custom API integrations without needing a vendor-specific collector or relying on external developers.

In a REST API Context collector, you can tailor the API request itself, as well as how it's authenticated and processed. You can also view the extracted data that is returned in the API response. When you navigate to Context Management to begin creating a corresponding context table, the extracted data is useful to ensure you configure source attributes in the table appropriately, according to the JSON schema of the API response.

In Context Management, REST API context tables do not map, by default, to a set of specific user, device, or other attributes. Instead, you have the flexibility to customize the attribute mapping for any of the source attributes returned by the API response in the collector, including first level, nested, and array attributes. You can map them to target attributes that are compliant with the Exabeam common user information model. This model defines standardized user, device, or other objects for security content across Exabeam products. You also have the option to map the source attributes to existing or newly-created custom attributes.

In the Context Management service, the REST API user, device, and other options are available as separate tiles on the Context Library tab. To create a REST API context table, you must first have a REST API Context cloud collector configured and running in the Exabeam Cloud Collectors service. You also need to view the extracted data, which is available in the collector itself, to determine which attributes to include in the context table and how to configure them. Then you can create the context table and it can begin processing the data sent from the cloud collector.

Note

Data in a REST API context table is refreshed according to the Collection Interval configured in the corresponding REST API Context cloud collector. For information about configuring this interval, see Configure the REST API Context Cloud Collector in the Get Started with Collector Onboarding Guide.

For more information, see the following sections: