Good evening,
I am trying to integrate BitDefender Gravity Zone. As you many may know is a cloud service. There are 2 steps 2 this:
1.- Generate a token authentication
2.-Enable the modules/log types with a CURL instruction
3.- Perform an http poll to get the logs once number 2 is done.
My problem is number 2. The curl instruction invokes the bitdefender URL and at the same time it addresses a reference to the siem with authentication. All the guides reference QRadar or Splunk... does anybody have any experience on this?