---
title: "Infocyte collector"
canonical: "https://docs.devo.com/space/latest/94656463/Infocyte%20collector"
format: markdown
---
> Macro (toc)

## <span style="color: #172b4d">Service description</span>

Veteran-founded [Infocyte](https://www.infocyte.com/) is the only Managed Detection and Response (MDR) provider solely focused on detection and response, enabling you to deploy it with your existing Endpoint Protection Platform (EPP) investments or MS Defender. Infocyte also provides Microsoft 365 Security within its platform, making compliance simple.

Infocyte guarantees that we will respond to a security event in 60 minutes or less. We help keep your events from becoming incidents.

## <span style="color: #172b4d">Data source description</span>

| **Data source** | *AlertDetails* |
| --- | --- |
| **Data table** | `mdr.infocyte.alertdetails` |
| **Collector service** | *alert_details* |
| **Remote endpoint** | `https://{subdomain}.infocyte.com/api/AlertDetails` |
| **Description** | *AlertDetails *endpoint finds all alert instances of the model matched by filter from the remote data source. |

## Vendor setup

In order to configure the Devo | Infocyte Collector, you need to create an API token that will be used to authenticate API requests.

1. Login to your Infocyte console.
2. Create an API token in the Web Console in your profile or Admin panel.

## Run the collector

Once the data source is configured, you can either send us the required information if you want us to host and manage the collector for you (<u>Cloud collector</u>), or deploy and host the collector in your own machine using a Docker image (<u>On-premise collector</u>).

> Macro (rw-ui-tabs-macro)
> 
> > Macro (rw-tab)
> 
> We use a piece of software called Collector Server to host and manage all our available collectors.
> 
> To enable the collector for a customer:
> 
> 1. In the **Collector Server** **GUI**, access the **domain** in which you want this instance to be created.
> 2. Click **Add Collector** and find **MVware Carbon Black Cloud - Integrations Factory**.
> 3. In the **Version** field, select the latest value.
> 4. In the **Collector Name** field, set the value you prefer (this name must be unique inside the same Collector Server domain).
> 5. In the sending method select **Direct Send. Direct Send** configuration is optional for collectors that create `Table` events, but mandatory for those that create `Lookups`.
> 6. In the **Parameters** section, establish the **Collector Parameters** as follows below:
> 
> ### Editing the JSON configuration
> 
> ```
> {
>   "global_overrides":{
>     "debug": <debug_value>
>   },
>   "inputs": {
>     "infocyte": {
>       "id": "<input_id>",
>       "enabled": <input_status>,
>       "requests_per_second": <requests_per_second>,
>       "credentials": {
>         "customer_id": "<customer_subdomain>",
>         "access_token": "<access_token_value>"
>       },
>       "services": {
>         "alert_details": {
>           "request_period_in_seconds": <request_period_in_seconds>,
>           "start_time": "<start_time>",
>           "tag": "<custom_tag>",
>           "skip_filter_validation": <skip_filter>,
>           "filters": <filters_object>
>         }
>       }
>     }
>   }
> }
> ```
> 
> > ℹ️ All defined service entities will be executed by the collector. If you do not want to run any of them, just remove the entity from the `services` object.
> 
> Please replace the placeholders with real world values following the description table below:
> 
> |  |  |  |  |  |
> | --- | --- | --- | --- | --- |
> | **Parameter** | **Data Type** | **Type** | **Value Range / Format** | **Details** |
> | `debug_value` | `bool` | `Mandatory` | `false` / `true` | Use this param to enable or disable the debug logging level. |
> | `input_id` | `int` | `Mandatory` | Minimum length: 1  
> Maximum length: 5 | Use this param to give an unique id to this input service. |
> | `input_status` | `bool` | `Mandatory` | `false` / `true` | If the value is `true`, the input definition will be executed. If the value is `false`, the service will be ignored. |
> | `requests_per_second` | `int` | `Optional` | Minimum value: 1 | Customize the maximum number of API requests per second. If not used, the default setting will be used: `100000` requests/sec.<br>> 📝 This parameter can be left blank, removed or commented. |
> | `customer_subdomain` | `str` | `Mandatory` | Minimum length: 1 | Set up here your subdomain name. Please do not include anything else. This value will be used as follows: http://`subdomain`.infocyte.com |
> | `access_token_value` | `str` | `Mandatory` | Minimum length: 1 | Set up here your access token created in the Infocyte console. |
> | `request_period_in_seconds` | `int` | `Optional` | Minimum length: 1 | Period in seconds used between each data pulling, this value will overwrite the default value (300 seconds)<br>> 📝 This parameter can be removed or commented. |
> | `start_time` | `str` | `Optional` | UTC with format: `YYYY-mm-ddTHH:MM:SS.sssZ` | By default, the collector is ready to download all available alerts since it is first activated. This configuration allows you to set a custom date as the beginning of the period to download. This allows downloading historical data (1 month back for example) before downloading new events.<br>> 📝 This parameter can be removed or commented. |
> | `tag` | `str` | `Optional` | `my.app.level3.level4` | Set this setting to ingest the events of this service in a custom Devo target table. Default value: `mdr.infocyte.alertdetails`<br>> 📝 This parameter can be removed or commented. |
> | `skip_filter` | `bool` | `Optional` | `false` / `true` | Set this setting to bypass filter validation, useful when filter is too complex for being validated with the simple implemented validation method. Default value: `false`<br>> 📝 This parameter can be removed or commented. |
> | `filters_object` | `object` | `Optional` | Visit [https://loopback.io/doc/en/lb3/Where-filter.html](https://loopback.io/doc/en/lb3/Where-filter.html) for extra details. | Filter to apply when executing the requests against Infocyte API (default value: "no filters"). You can use some of the following examples:<br>Specific `hostname` value:<br>```
> "filters": [
>   "hostname":
>     "eq": "host1.name.com",
> ],
> ```<br>Two different `hostname` values:<br>```
> "filters": [
>   "or": [
>     "hostname": "host1.name.com",
>     "hostname": "host2.name.com"  
>   ],
> ],
> ```<br>All `hostname` values except two specific ones:<br>```
> "filters": [
>   "and": [
>     "hostname": {
>       "neq": "host1.name.com"
>     },
>     "hostname": {
>       "neq": "host2.name.com"
>     }
>   ]
> ]
> ```<br>> 📝 This parameter can be removed or commented. |
> 
> > Macro (rw-tab)
> 
> This data collector can be run in any machine that has the Docker service available because it should be executed as a docker container. The following sections explain how to prepare all the required setup for having the data collector running.
> 
> ### Structure
> 
> The following directory structure should be created for being used when running the Infocyte collector:
> 
> ```
> <any_directory>
> └── devo-collectors/
>     └── devo-collector-infocyte/
>           ├── certs/
>           │ ├── chain.crt
>           │ ├── <your_domain>.key
>           │ └── <your_domain>.crt
>           └── config/
>               └── config-infocyte.yaml
> ```
> 
> ### Devo credentials
> 
> In Devo, go to **Administration → Credentials → X.509 Certificates**, download the **Certificate**, **Private key** and **Chain CA** and save them in `<devo-collector-infocyte-/certs/`. Learn more about security credentials in Devo [here](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94763701).
> 
> ![image](media://7a42ac29-dbde-4482-bd0e-48cd13687f7f)
> 
> ### Editing the config.yaml file
> 
> ```
> globals:
>   debug: true
>   id: <collector_id>
>   name: <collector_name>
>   persistence:
>     type: filesystem
>     config:
>       directory_name: state
>   multiprocessing: <multiprocessing_mode>
> 
> outputs:
>   devo_1:
>     type: devo_platform
>     config:
>       address: <devo_address>
>       port: 443
>       type: SSL
>       chain: <chain_filename>
>       cert: <cert_filename>
>       key: <key_filename>
> inputs:
>   infocyte:
>     id: <input_id>
>     enabled: <input_status>
>     requests_per_second: <request_per_second>
>     credentials:
>       customer_id: <customer_subdomain>
>       access_token: <access_token_value>
>   services:
>     alert_details: 
>       request_period_in_seconds: <request_period_in_seconds>
>       start_time: <start_time>
>       tag: <custom_tag>
>       skip_filter_validation: <skip_filter>
>       filters: <filters_object>
> ```
> 
> Replace the placeholders with your corresponding values:
> 
> | **Parameter** | **Data type** | **Type** | **Value range** | **Details** |
> | --- | --- | --- | --- | --- |
> | `collector_id` | `int` | `Mandatory` | Minimum length: 1  
> Maximum length: 5 | Use this param to give a unique ID to this collector. |
> | `collector_name` | `str` | `Mandatory` | Minimum length: 1  
> Maximum length: 10 | Use this param to give a valid name to this collector. |
> | `multiprocessing_mode` | `bool` | `Mandatory` | `false `/ `true` | If the value is `true`, the collector will run using a multiprocessing architecture. If the value is `false`, the collector will use only one CPU. |
> | `devo_address` | `str` | `Mandatory` | `collector-us.devo.io`  
> `collector-eu.devo.io` | Use this param to identify the Devo Cloud where the events will be sent. |
> | `chain_filename` | `str` | `Mandatory` | Minimum length: 4  
> Maximum length: 20 | Use this param to identify the `chain.cert`  file downloaded from your Devo domain. Usually this file's name is `chain.crt` |
> | `cert_filename` | `str` | `Mandatory` | Minimum length: 4  
> Maximum length: 20 | Use this param to identify the `file.cert` downloaded from your Devo domain. |
> | `key_filename` | `str` | `Mandatory` | Minimum length: 4  
> Maximum length: 20 | Use this param to identify the `file.key` downloaded from your Devo domain. |
> | `input_id` | `int` | `Mandatory` | Minimum length: 1  
> Maximum length: 5 | Use this param to give a unique ID to this input service. |
> | `input_status` | `bool` | `Mandatory` | false / true | If the value is `true`, the input definition will be executed. If the value is `false`, the service will be ignored. |
> | `requests_per_second` | `int` | `Optional` | Minimum value: 1 | Customize the maximum number of API requests per second. If not used, the default setting will be used: 100000 requests/sec.<br>This parameter can be left blank, removed or commented. |
> | `customer_subdomain` | `str` | `Mandatory` | Minimum length: 1 | Set up here your subdomain name. Please do not include anything else. This value will be used as follows: [http://subdomain.infocyte.com](http://subdomain.infocyte.com/) |
> | `access_token_value` | `str` | `Mandatory` | Minimum length: 1 | Set up here your access token created in the Infocyte console. |
> | `request_period_in_seconds` | `int` | `Optional` | Minimum length: 1 | Period in seconds used between each data pulling, this value will overwrite the default value (300 seconds)<br>This parameter can be removed or commented. |
> | `start_time` | `str` | `Optional` | UTC with format `YYYY-mm-ddTHH:MM:SS.sssZ` | By default, the collector is ready to download all available alerts since it is first activated. This configuration allows you to set a custom date as the beginning of the period to download. This allows downloading historical data (1 month back for example) before downloading new events.<br>This parameter can be removed or commented. |
> | `tag` | `str` | `Optional` | `my.app.level3.level4` | Set this setting to ingest the events of this service in a custom Devo target table. Default value is `mdr.infocyte.alertdetails`<br>This parameter can be removed or commented. |
> | `skip_filter` | `bool` | `Optional` | `false `/ `true` | Set this setting to bypass filter validation, useful when filter is too complex for being validated with the simple implemented validation method. Default value: false<br>This parameter can be removed or commented. |
> | `filters_object` | `object` | `Optional` | Visit [Where filter | LoopBack Documentation](https://loopback.io/doc/en/lb3/Where-filter.html) for extra details. | Filter to apply when executing the requests against Infocyte API (default value is `no filters`). You can use some of the following examples:<br>Specific hostname value:<br>```
> filters:
>   - hostname:
>       eq: host1.name.com
> ```<br>Two different hostname values:<br>```
> filters:
>   - or:
>     - hostname:
>         eq: host1.name.com
>     - hostname:
>         eq: host2.name.com
> ```<br>All hostname values except two specific ones:<br>```
> filters:
>   - and:
>     - hostname:
>         neq: host1.name.com
>     - hostname:
>         neq: host2.name.com
> ```<br>This parameter can be removed or commented. |
> 
> ### Download the Docker image
> 
> The collector should be deployed as a Docker container. Download the Docker image of the collector as a .tgz file by clicking the link in the following table:
> 
> | **Collector Docker image** | **SHA-256 hash** |
> | --- | --- |
> | [collector-infocyte-docker-image-1.2.0.tgz](https://drive.google.com/file/d/1W8WCLeveMeqWbyt6aUbSI79VNn61ZF21/view?usp=sharing) | `12d2175287e28023405d01d972e9306b06bf4f1b64ae8794594f8a159a67ea12` |
> 
> Use the following command to add the Docker image to the system:
> 
> ```
> gunzip -c collector-infocyte-docker-image-<version>.tgz | docker load
> ```
> 
> > ℹ️ Once the Docker image is imported, it will show the real name of the Docker image (including version info). Replace "`<version>`" with a proper value.
> 
> The Docker image can be deployed on the following services:
> 
> #### Docker
> 
> Execute the following command on the root directory `<any_directory>/devo-collectors/infocyte/`
> 
> ```
> docker run \
> --name collector-infocyte\
> --volume $PWD/certs:/devo-collector/certs \
> --volume $PWD/config:/devo-collector/config \
> --volume $PWD/state:/devo-collector/state \
> --env CONFIG_FILE=config-infocyte.yaml \
> --rm -it docker.devo.internal/collector/infocyte:<version>
> ```
> 
> > ⚠️ Replace `<version>` with the required value.
> 
> #### Docker Compose
> 
> The following Docker Compose file can be used to execute the Docker container. It must be created in the `<any_directory>/devo-collectors/infocyte/` directory.
> 
> ```
> version: '3'
> services:
>   collector-infocyte:
>     image: docker.devo.com/collector/infocyte:${IMAGE_VERSION:-latest}
>     volumes:
>       - ./certs:/devo-collector/certs
>       - ./config:/devo-collector/config
>       - ./state:/devo-collector/state
>    environment:
>      - CONFIG_FILE=${CONFIG_FILE:-config-infocyte.yaml}
> ```
> 
> To run the container using docker-compose, execute the following command from the `<any_directory>/devo-collectors/infocyte/` directory:
> 
> ```
> IMAGE_VERSION=<version> docker-compose up -d
> ```
> 
> > ⚠️ Replace `<version>` with the required value.

## Change Log for 1.x.x

| **Release** | **Released on** | **Release type** | **Details** | **Recommendations** |
| --- | --- | --- | --- | --- |
| `v1.3.0` | 9/11/2023 | [IMPROVEMENT] | **Improvements:**<br>- Updated DCSDK from 1.4.1 to 1.9.2 | `Recommended version` |
| `v1.2.0` | 6/24/2022 | [NEW FEATURE]  
[IMPROVEMENT] | **This release includes the following changes:**<br>- The resilience has been improved with a new feature that restart the collector when the Devo connections is lost and it cannot be recovered.
- All `critical` and `high` vulnerabilities have been mitigated. | `Update` |