Sumo Logic Cloud SIEM (v1.1.36)

Sumo Logic Cloud SIEM provides threat detection and incident response for modern IT environments. This content pack will allow you to apply automation to perform actual SOC analyst workflows. Using this content pack you will be able to fetch Incidents via Insights, update status of an Insight, add items to match list, add Threat Intel Indicators to Threat Intel Sources, and so on.

Author
Sumo Logic
Support
partner
URL
https://www.sumologic.com/solutions/cloud-siem-enterprise/
Categories
Analytics & SIEM

Incident fields (8)

Integrations (1)

Layouts (2)

Scripts (2)

README

The integration in this pack enables interactions with Sumo Logic Cloud SIEM. It can be used to fetch Incidents via Insights, update status of an Insight, add items to match list, search Entities/Signals/Insights/Threat Intel indicators, and more.

What does this pack do?

This pack enables you to run commands that:

Note: This pack replaces the legacy JASK pack. For further details about the migration from JASK, visit our reference docs.