Monitor Security Incident Response Integrations

Santiago Musca
Tera Expert

Hi Everyone!

 

I'm trying to make it possible for us to automatically monitor de integrations for SIR without the need to check if a Token is expired, if the the data was successfully transfered, etc.

 

The idea is to be able to get a notification once an integration failed or errored. For example if RecordedFuture integration fails, it will insert a log on the log table, but I cannot query the table due to the possible performance impact. So I'm trying to see if anyone have came across with the idea.

 

I was able to leverage watchdog alert rules for VR and for TISC since they have a specific table where the integration jobs are running.

 

Is there anything similar for SIR? 

0 REPLIES 0