Audits
Overview
Get a list of Agari DMARC Protection audits by domain, user or organization through the Agari API using the HTTP Pull Listener.
HTTP Pull Listener configuration
In Falcon Onum, go to the Listeners area and click New Listener > HTTP Pull. Give a name to your new Listener and enter the following data:
Parameters
Add the following parameter:
Name -
domainValue - Enter your Agari DMARC Protection domain name.
Secrets
You must define these credentials in Onum:
client_idwill reference your Agari DMARC Protection API Application ID.client_secretwill reference your Agari DMARC Protection Application secret key.
To do it, click Add element and enter a Name for the secret (in this case, client_id). Then, click the Value field and select New secret to create a new one:
Give the secret a Name.
Turn off the Expiration date option.
Click Add new value and paste the secret corresponding to the value.
Click Save.
You can now select the secret you just created in the Value field list. Repeat the process for the client_secret.
Learn more about secrets in Onum in this article.
Setup
After entering the required parameters and secrets, you can choose to manually enter the rest of configuration fields, or simply paste the given YAML:
Audits by domain
Toggle ON the Config as YAML option to enable a free text field where you can paste the following YAML:
Temporal Window
Toggle ON to add a temporal window for events. This repeatedly shifts the time window over which data is collected.
Duration* -
5mOffset* -
5mFormat* -
RFC3339
Authentication
Toggle ON to configure the authentication phase. This is required to get the token to pull data using OAuth.
Type* -
TokenToken Retrieve Based Authentication
Method* -
POSTURL* -
${parameters.domain}/v1/cp/oauth/tokenHeaders
Name -
Content-typeValue -
application/x-www-form-urlencodedName -
AcceptValue -
application/json
Body Type* -
UrlEncodedBody Params
Name -
client_idValue -
'${secrets.client_id}'Name -
client_secretValue -
'${secrets.client_secret'
Token path* -
.access_tokenAuth Injection
In* -
headerName* -
authorizationPrefix -
'Bearer 'Suffix -
''
Enumeration Phase
Toggle ON and enter the following:
Pagination Type* -
Offset/LimitZero Index* -
falseLimit* -
200Request
Response Type -
JSONMethod* -
GETURL* -
${parameters.domain}/v1/cp/domainsHeaders
Name -
acceptValue -
application/json
Query Params
Name -
offsetValue -
${pagination.offset}Name -
limitValue -
${pagination.limit}
Output
Select* -
[.domains[].id]Map -
.Output Mode* -
element
Collection Phase
Inputs
Name -
domainIdExpression -
.Format -
""
Pagination Type* -
noneZero Index* -
falseRequest
Response Type* -
JSONMethod* -
GETURL* -
${parameters.domain}/v1/cp/auditsHeaders
Name -
acceptValue -
application/json
Query Params
Name -
start_dateValue -
${temporalWindow.from}Name -
end_dateValue -
${temporalWindow.to}Name -
object_typeValue -
domainName -
object_idValue -
${inputs.domainId}
Output
Select* -
.audits.entriesMap -
.Output Mode* -
element
Audits by organization
Toggle ON the Config as YAML option to enable a free text field where you can paste the following YAML:
Temporal Window
Toggle ON to add a temporal window for events. This repeatedly shifts the time window over which data is collected.
Duration* -
5mOffset* -
5mFormat* -
RFC3339
Authentication
Toggle ON to configure the authentication phase. This is required to get the token to pull data using OAuth.
Type* -
TokenToken Retrieve Based Authentication
Method* -
POSTURL* -
${parameters.domain}/v1/cp/oauth/tokenHeaders
Name -
Content-typeValue -
application/x-www-form-urlencodedName -
AcceptValue -
application/json
Body Type* -
UrlEncodedBody Params
Name -
client_idValue -
'${secrets.client_id}'Name -
client_secretValue -
'${secrets.client_secret'
Token path* -
.access_tokenAuth Injection
In* -
headerName* -
authorizationPrefix -
'Bearer 'Suffix -
''
Enumeration Phase
Toggle ON and enter the following:
Pagination Type* -
Offset/LimitZero Index* -
falseLimit* -
200Request
Response Type -
JSONMethod* -
GETURL* -
${parameters.domain}/v1/cp/organizationsHeaders
Name -
acceptValue -
application/json
Query Params
Name -
offsetValue -
${pagination.offset}Name -
limitValue -
${pagination.limit}
Output
Select* -
[.organizations[].id]Map -
.Output Mode* -
element
Collection Phase
Inputs
Name -
orgIdExpression -
.Format -
""
Pagination Type* -
noneZero Index* -
falseRequest
Response Type* -
JSONMethod* -
GETURL* -
${parameters.domain}/v1/cp/auditsHeaders
Name -
acceptValue -
application/json
Query Params
Name -
start_dateValue -
${temporalWindow.from}Name -
end_dateValue -
${temporalWindow.to}Name -
object_typeValue -
organizationName -
object_idValue -
${inputs.orgId}
Output
Select* -
.audits.entriesMap -
.Output Mode* -
element
Audits by user
Toggle ON the Config as YAML option to enable a free text field where you can paste the following YAML:
Temporal Window
Toggle ON to add a temporal window for events. This repeatedly shifts the time window over which data is collected.
Duration* -
5mOffset* -
5mFormat* -
RFC3339
Authentication
Toggle ON to configure the authentication phase. This is required to get the token to pull data using OAuth.
Type* -
TokenToken Retrieve Based Authentication
Method* -
POSTURL* -
${parameters.domain}/v1/cp/oauth/tokenHeaders
Name -
Content-typeValue -
application/x-www-form-urlencodedName -
AcceptValue -
application/json
Body Type* -
UrlEncodedBody Params
Name -
client_idValue -
'${secrets.client_id}'Name -
client_secretValue -
'${secrets.client_secret'
Token path* -
.access_tokenAuth Injection
In* -
headerName* -
authorizationPrefix -
'Bearer 'Suffix -
''
Enumeration Phase
Toggle ON and enter the following:
Pagination Type* -
Offset/LimitZero Index* -
falseLimit* -
200Request
Response Type -
JSONMethod* -
GETURL* -
${parameters.domain}/v1/cp/usersHeaders
Name -
acceptValue -
application/json
Query Params
Name -
offsetValue -
${pagination.offset}Name -
limitValue -
${pagination.limit}
Output
Select* -
[.users[].id]Map -
.Output Mode* -
element
Collection Phase
Inputs
Name -
userIdExpression -
.Format -
""
Pagination Type* -
noneZero Index* -
falseRequest
Response Type* -
JSONMethod* -
GETURL* -
${parameters.domain}/v1/cp/auditsHeaders
Name -
acceptValue -
application/json
Query Params
Name -
start_dateValue -
${temporalWindow.from}Name -
end_dateValue -
${temporalWindow.to}Name -
object_typeValue -
userName -
object_idValue -
${inputs.userId}
Output
Select* -
.audits.entriesMap -
.Output Mode* -
element
When you're done, click Create labels to move on to the next step and define the required Labels if needed.
Last updated
Was this helpful?

