Box
- Details
- Content
- Dependencies
- Version History
Manage Box users and collect events.
Box
This pack includes Cortex XSIAM content.
This pack includes
- Collection of Box event log messages.
- Log Normalization - XDM mapping for key event types.
Supported Event Types
- All event types from ./2.0/events API call.
Time Zone support for XSIAM
For supporting Time Zone parsing, time should be set to UTC +0000 Product documentation:
- Sign into your Box account.
- Click your initials in the top-right corner to open the Account Menu.
- Click Account Settings.
- The Account tab should open by default. Locate the General Options section.
- Select your preferred timezone from the pulldown menu under Time Zone.
- Click Save Changes in the top right to save your settings.
Enabling Box Event Collector
To configure the Box Event Collector to receive log messages:
- Make sure you have the Box pack installed on your Cortex XSIAM tenant.
- Go to Settings → Configurations → Automation & Feed Integrations.
- In the search bar, type Box and click + Add instance.
- Follow the integration steps to send logs from Box to your Cortex XSIAM tenant.
| Name | Description |
|---|---|
Box Incident Incoming Mapper | Maps incoming Box incident fields. |
| Name | Description |
|---|---|
Box Source Owner Name | The name for the owner of the source. |
Box Source Created By Name | The name of the user who created the item. |
Box Source Owner ID | The owner ID for the source. |
Box Source Created By ID | The ID of the user who created the event. |
Box Source Parent Name | The name for the parent of the source. |
Box Source Parent ID | The ID for the parent of the source. |
| Name | Description |
|---|---|
Box Incident |
| Name | Description |
|---|---|
| Box v2 | Manage Box users. |
| Box (Deprecated) | Deprecated. Use the Box v2 integration instead. |
| Name | Description |
|---|---|
Box Incident |
| Name | Description |
|---|---|
Box Incident Incoming Mapper | Maps incoming Box incident fields. |
| Name | Description |
|---|---|
Box Source Owner ID | The owner ID for the source. |
Box Source Created By Name | The name of the user who created the item. |
Box Source Owner Name | The name for the owner of the source. |
Box Source Parent ID | The ID for the parent of the source. |
Box Source Parent Name | The name for the parent of the source. |
Box Source Created By ID | The ID of the user who created the event. |
| Name | Description |
|---|---|
Box Incident |
| Name | Description |
|---|---|
| Box Event Collector | Collect events from Box's logs. |
| Box v2 | Manage Box users. |
| Box (Deprecated) | Deprecated. Use the Box v2 integration instead. |
| Name | Description |
|---|---|
BoxEventCollector |
| Name | Description |
|---|---|
BoxEventCollector Parsing Rule |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Common Types | By: Cortex XSOAR |
| Pack Name | Pack By |
|---|---|
| Base | By: Cortex XSOAR |
Integrations
Box Event Collector
- Fixed an issue where the fetch-events command timed out on high-volume tenants because a single fetch attempted to drain the entire event backlog. Switched from limiting the number of events per API request to limiting the total number of events per fetch cycle via the new Maximum number of events per fetch parameter, and ensured the event stream position is persisted incrementally so the backlog drains gradually across successive fetches.
- Removed the Maximum number of events per page parameter (breaking change). The per-request page size is now fixed internally at the Box API maximum. Any previously configured value for this parameter no longer takes effect; use the new Maximum number of events per fetch parameter to control collection volume.
- Updated the box-get-events command by replacing its page_size argument with a limit argument (breaking change), which now caps the total number of events returned by the command. Any script or automation that passes page_size to this command must be updated to use limit.
- Updated the Docker image to: demisto/auth-utils:1.0.0.11206988.
- 45163
Download
PUBLISHER
PLATFORMS
INFO
| Certification | Certified | Read more |
| Supported By | Cortex | |
| Created | November 9, 2020 | |
| Last Release | August 27, 2026 |
WORKS WITH THE FOLLOWING INTEGRATIONS:


