Symantec ICDx

Integration version: 6.0

Configure Symantec ICDx integration in Google Security Operations

For detailed instructions on how to configure an integration inGoogle SecOps, seeConfigureintegrations.

Actions

Get Event

Description

Get event data by its ID.

Parameters

ParameterTypeDefault ValueDescription
Event UUIDStringN/AN/A

Use cases

N/A

Run On

This action runs on all entities.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result NameValue OptionsExample
is_successTrue/Falseis_success:False
JSON Result
N/A

Get Events Minutes Back

Description

Get events for query, by minutes back.

Parameters

ParameterTypeDefault ValueDescription
QueryStringN/ARequest query.
LimitStringN/AReceived events amount limit.
Minutes BackStringN/AFetch events minutes back parameter.
FieldsStringN/ASpecific event fields to bring(Comma separated.)

Use cases

N/A

Run On

This action runs on all entities.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result NameValue OptionsExample
4.0N/AN/A
JSON Result
N/A

Ping

Description

Test Symantec ICDx connectivity.

Parameters

N/A

Use cases

N/A

Run On

This action runs on all entities.

Action Results

Entity Enrichment

N/A

Insights

N/A

Script Result
Script Result NameValue OptionsExample
is_successTrue/Falseis_success:False
JSON Result
N/A

Connectors

Symantec ICDx query Connector

Description

Fetching events from Symantec ICDx server using a query.

Configure Symantec ICDx Query Connector in Google SecOps

For detailed instructions on how to configure a connector inGoogle SecOps, seeConfiguring theconnector.

Connector parameters

Use the following parameters to configure the connector:

ParameterTypeDefault ValueDescription
DeviceProductFieldStringdevice_productThe field name used to determine the device product.
EventClassIdStringnameThe field name used to determine the event name (sub-type).
PythonProcessTimeoutString60The timeout limit (in seconds) for the python process running current script.
API RootStringnullN/A
API TokenPasswordnullN/A
Verify SSLBooleanFALSEWhether to use son connection or not.
Search QueryStringnullN/A
Events LimitInteger10Max count of events to pull in one cycle. Example: 20
Max Days BackwardsInteger1Max number of days to fetch alerts since. Example: 3
Proxy Server AddressStringnullThe address of the proxy server to use.
Proxy UsernameStringnullThe proxy username to authenticate with.
Proxy PasswordPasswordnullThe proxy password to authenticate with.

Connector Rules

Proxy support

The connector supports proxy.

Whitelist/Blacklist

The connector supports Whitelist/Blacklist rules.

Need more help?Get answers from Community members and Google SecOps professionals.

Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026-02-18 UTC.