Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
Original file line number Diff line number Diff line change
Expand Up @@ -88,12 +88,7 @@ Access to the Automation Service is controlled by [role capabilities](/docs/mana

### Configure the connection for an integration resource

To use [integrations](/docs/platform-services/automation-service/automation-service-integrations), you must configure the connection for their resources.
1. [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Automation** and then select **Integrations** in the left nav bar. <br/>[**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu, select **Automation > Integrations**. You can also click the **Go To...** menu at the top of the screen and select **Integrations**.
1. Select the integration whose resource you want to configure the connection for.
1. Hover over the resource name and click the **Edit** button that appears.<br/><img src={useBaseUrl('img/cse/automations-edit-resource.png')} style={{border:'1px solid gray'}} alt="Edit a resource" width="800"/>
1. Enter the connection configuration needed by the resource. (Find the integration in [Integrations in App Central](/docs/platform-services/automation-service/app-central/integrations/) for configuration instructions.)<br/>What you enter is specific to the resource you're using. Each resource's configuration screen may be different, but in most cases, you will need information such as IP addresses, API tokens, usernames, and passwords for the application you're integrating with. For example, in the following screen enter the **API URL** and **API Key**. <br/><img src={useBaseUrl('img/cse/automations-edit-resource-2.png')} style={{border:'1px solid gray'}} alt="Edit a resource" width="400"/>
1. Click **Save** to save the configuration.
To use [integrations](/docs/platform-services/automation-service/automation-service-integrations), you must first configure the connection for their resources. See [Configure Authentication for Integrations](/docs/platform-services/automation-service/configure-authentication-for-integrations/).

## Actions limit

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,12 @@ In this section, we'll introduce the following concepts:
<p>Learn how to use App Central to get new applications and tools.</p>
</div>
</div>
<div className="box smallbox card">
<div className="container">
<a href="/docs/platform-services/automation-service/configure-authentication-for-integrations/"><img src={useBaseUrl('img/icons/security/siem-challenges.png')} alt="icon" width="40"/><h4>Configure Authentication for Integrations</h4></a>
<p>Learn how to configure authentication for integrations.</p>
</div>
</div>
<div className="box smallbox card">
<div className="container">
<a href="/docs/platform-services/automation-service/app-central/integrations/"><img src={useBaseUrl('img/icons/security/siem-challenges.png')} alt="icon" width="40"/><h4>Integrations in App Central</h4></a>
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,11 @@ Abnormal Security provides advanced email security to prevent credential phishin
* **Get Employee Identity Analysis** *(Enrichment)* - Get employee identity analysis (Genome) data.
* **Get Employee Information** *(Enrichment)* - Get employee information.

## Abnormal Security in Automation Service and Cloud SOAR
## Configure Abnormal Security in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation/).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,11 @@ An SSL certificate can be associated with one or more servers (IP address:port c
* I strongly recommend you to not use the aggressive version of the Botnet C2 IP blacklist as it definitely will cause false positives. If you want to reduce the amount of false positives, do not use this option. If you want to get maximum protection and do not care about false positives, you can enable the action by selecting the checkbox (not recommended).
* More info: 'https://sslbl.abuse.ch/'

## Abuse.ch SSLBL Feed in Automation Service and Cloud SOAR
## Configure Abuse.ch SSLBL Feed in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search/look for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,11 @@ Enrich IP addresses with reputation information gathered from AbuseIPDB.
4. Click on **Create Key**.
5. Copy the **API key**.

## Configure AbuseIPDB
## Configure AbuseIPDB in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
2. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,11 @@ Follow these steps to get your API key from Arconis.
1. Click **+ Create API Client** and enter a name. <br/><img src={useBaseUrl('/img/platform-services/automation-service/app-central/integrations/acronis/acronis-3.png')} style={{border:'1px solid gray'}} alt="acronis-3" width="400"/> <br/><img src={useBaseUrl('/img/platform-services/automation-service/app-central/integrations/acronis/acronis-4.png')} style={{border:'1px solid gray'}} alt="acronis-4" width="400"/>
1. Copy and save the Client ID, Secret, and Data center URL. <br/><img src={useBaseUrl('/img/platform-services/automation-service/app-central/integrations/acronis/acronis-5.png')} style={{border:'1px solid gray'}} alt="acronis-5" width="400"/>

## Acronis in Automation Service and Cloud SOAR
## Configure Acronis in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -76,7 +76,11 @@ If an existing Windows Server is not available, follow these steps to set up a n
1. After rebooting, log back in and open **Active Directory Users and Computers**.
1. Verify that the domain is properly configured.

## Active Directory V2 in Automation Service and Cloud SOAR
## Configure Active Directory V2 in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

### Required resources from an existing Active Directory installation

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,12 @@ Utilize user, group, and system information from Microsoft Active Directory.

* [LDAP3](https://github.com/cannatag/ldap3/blob/master/LICENSE.txt)

## Configure Active Directory in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* December 19, 2019 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,11 @@ Updated: Jul 18, 2023**
1. Sign in to the Airtable platform with your email ID and password. <br/><img src={useBaseUrl('/img/platform-services/automation-service/app-central/integrations/airtable/airtable-1.png')} style={{border:'1px solid gray'}} alt="airtable-1" width="800"/>
1. Create your token, refer to the [Developer hub page](https://airtable.com/developers/web/guides/personal-access-tokens).

## Airtable in Automation Service and Cloud SOAR
## Configure Airtable in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,11 @@ Updated: Jul 18, 2023***
1. Log in to the Akenza platform with your email and password and follow the link for configuration.
1. Create API key from GUI of Akenza by locating to API key and by clicking on the button Generate API Key.<br/><img src={useBaseUrl('/img/platform-services/automation-service/app-central/integrations/akenza/akenza-1.png')} style={{border:'1px solid gray'}} alt="akenza-1" width="800"/>

## Akenza in Automation Service and Cloud SOAR
## Configure Akenza in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,12 @@ Enrich incident evidence with threat intelligence data from AlienVault OTX.

Threat Intelligence-Reputation

## Configure AlienVault in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* October 3, 2019 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,12 @@ Search events, alarms, and update labels in AlienVault USM Anywhere.
* **Get Events AlienVault Daemon** (*Daemon*) - Automatically gather all available events.
* **Get Alarms AlienVault Daemon** (*Daemon*) - Automatically gather all available alarms.

## Configure AlienVault USM Anywhere in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* September 17, 2019 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,12 @@ Search events, alarms, and update labels in AlienVault USM Central.
* **List Deployments** (*Enrichment*) - List all available deployments.
* **AlienVault USM Central Alarms** (*Daemon*) - Automatically pull USM Central Alarms.

## Configure AlienVault USM Central in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* October 26, 2020 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,12 @@ Alleantia software is a reference vendor for factory automation, energy and util
* **Get History Alarms** (*Enrichment*) - Returns the historical list of the alarms in the IoT Server sorted by ascending time.
* **Get Alarm Configuration** (*Enrichment*) - Returns the information on an alarm configured on the IoT Server.

## Configure Alleantia in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* December 17, 2020 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,11 @@ alphaMountain provides up-to-date domain and IP intelligence for cybersecurity i

In order to get a free trial please visit [https://www.alphamountain.ai/contact/](https://www.alphamountain.ai/contact/) to get your license key.

## alphaMountain in Automation Service and Cloud SOAR
## Configure alphaMountain in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search/look for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ Anomali ThreatStream (previously known as ThreatStream Optic) is Threat Intellig
* **Add Observable** (*Containment*) - To import structured threat data (observables) into ThreatStream, without requiring approval of the imported data through the ThreatStream UI.
* **Update Observable Tags** (*Containment*) - Enables you to add observable tags in bulk.

## Configure Anomali ThreatStream in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* November 10, 2022 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,11 @@ Gather detonation data for files and URL using `ANY.RUN`.

Sign in to ANY.RUN. Click on your profile on the left menu. In the API and Limits tab generate your API KEY and copy it.

## ANY.RUN in Automation Service and Cloud SOAR
## Configure ANY.RUN in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,12 @@ Utilize APIVOID to gather enrichment data during incident investigations.
* **Site Trustworthiness** (*Enrichment*) - Gather a site's trustworthiness score.
* **URL Reputation** (*Enrichment*) - Gather URL reputation information.

## Configure APIVoid in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* August 14, 2020 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,12 @@ Gather detail-rich data from Netscout Arbor alerts.
* **Mitigation Ongoing Polling** (*Enrichment*) - Presents data on whether the alert is still actively being mitigated.
* **Arbor Alerts Daemon** (*Daemon*) - Automatically pass alerts to Cloud SOAR.

## Configure Arbor in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* May 22, 2020 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,11 @@ Arcanna enables experts to train context-aware AI models which encompass their k

Log in to Arcanna platform using your credentials login on Arcanna AI using [this](https://elements.withsecure.com/) url.

## Arcanna in Automation Service and Cloud SOAR
## Configure Arcanna in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search/look for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,12 @@ Work with cases and active lists in Micro Focus ArcSight ESM.
* **Get Cases Arcsight ESM Daemon** (*Daemon*) - Automatically pull ArcSight ESM Cases.
* **Get Security Event** (*Enrichment*) - Get Security Event related to Case.

## Configure ArcSight ESM in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* February 7, 2019 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,12 @@ Query events in Micro Focus ArcSight Logger.

* **Search Into Events Arcsight** (*Enrichment*) - Search events in ArcSight Logger.

## Configure ArcSight Logger in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* January 31, 2019 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,12 @@ Armorblox secures enterprise communications over email and other cloud office ap
* **List Incidents** *(Enrichment)* - Get a list of all the Incidents detected by Armorblox.
* **Update Incident Action** *(Containment)* - Update the action to be taken for an incident's objects.

## Configure Armorblox in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* September 4, 2023 (v1.0) - First upload
Original file line number Diff line number Diff line change
Expand Up @@ -19,10 +19,16 @@ Atlassian Confluence is a collaborative workspace tool for teams to create, shar
* **List Pages** *(Enrichment)* - Returns all pages.
* **List Spaces** *(Enrichment)* - Returns all spaces.

## Atlassian Confluence configuration
## Configure Atlassian Confluence configuration

To retrieve the API token, please refer to the following [guide](https://support.atlassian.com/atlassian-account/docs/manage-api-tokens-for-your-atlassian-account/).

## Atlassian Confluenc in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* October 13, 2023 - First upload
Original file line number Diff line number Diff line change
Expand Up @@ -49,7 +49,11 @@ A revoked token no longer works and is permanently removed from your account. If
1. Select **Revoke** next to the API token that you want to revoke.
1. To revoke all API tokens for your account, select **Revoke all API tokens**.

## Atlassian Jira Cloud in Automation Service and Cloud SOAR
## Configure Atlassian Jira Cloud in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,11 @@ A revoked token no longer works and is permanently removed from your account. If
1. Select **Revoke** next to the API token that you want to revoke.
1. To revoke all API tokens for your account, select **Revoke all API tokens**.

## Atlassian Jira V2 in Automation Service and Cloud SOAR
## Configure Atlassian Jira V2 in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

1. Access integrations in the [Automation Service](/docs/platform-services/automation-service/automation-service-integrations/#view-integrations) or [Cloud SOAR](/docs/cloud-soar/automation).
1. After the list of the integrations appears, search for the integration and click on the row.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,12 @@ This integration is built specifically for Jira OnPrem (Server and Data Center)

Ticketing System

## Configure Atlassian Jira in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* June 3, 2019 - First upload
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -74,6 +74,12 @@ To run the other actions, you need to have an API from **Team Integrations**:
Please keep in mind that the API keys of the team integrations can only be used for the alerts/incidents of the specific team and the team-based configurations, whereas the API keys of the global integrations can be used for all of the API requests, including account-based configurations.
:::

## Configure Atlassian OpsGenie in Automation Service and Cloud SOAR

import IntegrationsAuth from '../../../../reuse/integrations-authentication.md';

<IntegrationsAuth/>

## Change Log

* March 22, 2024 - First upload
Expand Down
Loading