SumoLogicSEC
Freeing the analyst with autonomous decisions.
- Category
- Analytics & SIEM
- Pack
- SumoLogic_Cloud_SIEM
Configuration parameters
- api_endpoint — Sumo Logic API Endpoint (required)
- instance_endpoint — Sumo Logic Instance Endpoint
- isFetch — Fetch incidents
- incidentType — Incident type
- access_id — Access ID (required)
- access_key — Access Key (required)
- incidentFetchInterval — Incidents Fetch Interval
- max_fetch — Fetch Limit
- fetch_query — Override default fetch query
- first_fetch — First fetch time
- pull_signals — Pull associated Sumo Logic Signals as Incidents
- mirror_direction — Incident Mirroring Direction
- close_incident — Close Mirrored XSOAR Incident
- close_insight — Close Mirrored Sumo Logic Insight
- record_summary_fields — Override Record Summary Fields
Commands (14)
- sumologic-sec-entity-get-details — Get entity details for a specific entity ID.
- sumologic-sec-entity-search — Search entities using the available filters.
- sumologic-sec-insight-add-comment — Add a comment for a specific Insight ID (Users can post and update comments on the Sumo Logic Cloud SIEM portal for any Insight ID).
- sumologic-sec-insight-get-comments — Get comments for a specific Insight ID (Users can post and update comments on the Sumo Logic Cloud SIEM portal for any Insight ID).
- sumologic-sec-insight-get-details — Get Insight details for a specific Insight ID.
- sumologic-sec-insight-search — Search insights using available filters.
- sumologic-sec-insight-set-status — Change the status of an Insight.
- sumologic-sec-match-list-get — Get match lists.
- sumologic-sec-match-list-update — Add an item to a match list.
- sumologic-sec-signal-get-details — Get Signal details for a specific Signal ID. Signal details command references signals in Sumo Logic Cloud SIEM which are created when records exhibit suspicious properties and mate with patterns or other detection logic.
- sumologic-sec-signal-search — Search signals using available filters.
- sumologic-sec-threat-intel-get-sources — Get Threat Intel Sources.
- sumologic-sec-threat-intel-search-indicators — Search Threat Intel Indicators.
- sumologic-sec-threat-intel-update-source — Add a Threat Intel Indicator to an Threat Intel Source.