From 3142629f13ec78d9660edb362fd81721ee6a06f6 Mon Sep 17 00:00:00 2001 From: Jagadisha V Date: Mon, 18 Aug 2025 18:50:20 +0530 Subject: [PATCH 01/11] Extrahop RevealX 360 app doc --- blog-service/2025-08-20-apps.md | 12 ++ cid-redirects.json | 1 + .../product-list/product-list-a-l.md | 2 +- .../webhooks/extrahop-revealx-360.md | 169 ++++++++++++++++++ sidebars.ts | 1 + .../send-data/extrahop-revealx-360-icon.png | Bin 0 -> 13766 bytes 6 files changed, 184 insertions(+), 1 deletion(-) create mode 100644 blog-service/2025-08-20-apps.md create mode 100644 docs/integrations/webhooks/extrahop-revealx-360.md create mode 100644 static/img/send-data/extrahop-revealx-360-icon.png diff --git a/blog-service/2025-08-20-apps.md b/blog-service/2025-08-20-apps.md new file mode 100644 index 0000000000..007eabacd2 --- /dev/null +++ b/blog-service/2025-08-20-apps.md @@ -0,0 +1,12 @@ +--- +title: Extrahop RevealX 360 (Apps) +image: https://help.sumologic.com/img/reuse/rss-image.jpg +keywords: + - apps + - extrahop-revealx-360 +hide_table_of_contents: true +--- + +import useBaseUrl from '@docusaurus/useBaseUrl'; + +We're excited to introduce the new Extrahop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360). diff --git a/cid-redirects.json b/cid-redirects.json index 0a25966d48..8885691eec 100644 --- a/cid-redirects.json +++ b/cid-redirects.json @@ -1636,6 +1636,7 @@ "/cid/10210": "/docs/integrations/saas-cloud/proofpoint-tap", "/cid/10202": "/docs/integrations/saas-cloud/mimecast", "/cid/12222": "/docs/integrations/webhooks/snyk", + "/cid/12223": "/docs/integrations/webhooks/extrahop-revealx-360", "/cid/1119": "/docs/integrations/saas-cloud/druva", "/cid/10191": "/docs/integrations/saas-cloud/akamai-datastream", "/cid/10194": "/docs/integrations/saas-cloud/proofpoint-on-demand", diff --git a/docs/integrations/product-list/product-list-a-l.md b/docs/integrations/product-list/product-list-a-l.md index 0f6543bafc..6c66f268a8 100644 --- a/docs/integrations/product-list/product-list-a-l.md +++ b/docs/integrations/product-list/product-list-a-l.md @@ -219,7 +219,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [ | Thumbnail icon | [ESET](https://www.eset.com/us/) | Cloud SIEM integration: [ESET](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/ced86de0-64e4-4e7c-ae25-fb5b3dff3cb8.md) | | Thumbnail icon | [Exabeam](https://www.exabeam.com/) | Cloud SIEM integration: [Exabeam](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/9d2d799d-2d6c-4894-a46f-0cce00641bcb.md) | | Thumbnail icon | [Exploit Database](https://www.exploit-db.com/) | Automation integration: [Exploit Database](/docs/platform-services/automation-service/app-central/integrations/exploit-database/) | -| Thumbnail icon | [ExtraHop](https://www.extrahop.com/) | Cloud SIEM integration: [Extrahop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md)
Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) | +| Thumbnail icon | [ExtraHop](https://www.extrahop.com/) | App:
- [Extrahop RevealX 360](/docs/integrations/webhooks/extrahop-revealx-360)
- Cloud SIEM integration: [Extrahop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md)
Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) | ## F diff --git a/docs/integrations/webhooks/extrahop-revealx-360.md b/docs/integrations/webhooks/extrahop-revealx-360.md new file mode 100644 index 0000000000..cc05f52559 --- /dev/null +++ b/docs/integrations/webhooks/extrahop-revealx-360.md @@ -0,0 +1,169 @@ +--- +id: extrahop-revealx-360 +title: Extrahop RevealX 360 +sidebar_label: Extrahop RevealX 360 +description: The Extrahop RevealX 360 app for Sumo Logic provides security analysts with critical visibility into your Extrahop RevealX 360 environment. +--- + +import useBaseUrl from '@docusaurus/useBaseUrl'; + +extrahop-revealx-360-icon + +The Extrahop RevealX 360 app offers powerful network detection and response capabilities, providing organisations with in-depth visibility into security threats throughout their environment. By centralizing detection data such as total detections, average risk scores, MITRE attack techniques, and destination device activity, this app allows security teams to quickly identify, prioritize, and investigate suspicious activities. + +By leveraging real-time metrics and contextual threat information, the app highlights patterns of malicious behavior, high-risk destinations, and devices originating from embargoed locations. This insight helps teams monitor evolving risks, identify vulnerable assets, and understand the tactics and techniques targeting their networks. + +With its comprehensive detection summaries, geographical breakdowns, and detailed device-level insights, the Extrahop RevealX 360 app empowers organizations to respond effectively to emerging threats. By maintaining a clear view of their security posture, teams can act swiftly, reduce dwell time, and strengthen defenses to protect critical systems and data. + +:::info +This app includes [built-in monitors](#extrahop-revealx-360-alerts). For details on creating custom monitors, refer to [Create monitors for Extrahop RevealX 360 app](#create-monitors-for-extrahop-revealx-360-app). +::: + +## Log types + +The Sumo Logic app for Extrahop RevealX 360 ingests [detection events](https://docs.extrahop.com/current/detections-create-notification-rule/) via a webhook. + +## Sample log messages + +```json title="Detection log" +{ + "mitre_techniques": [ + { + "id": "T1021", + "name": "Remote Services" + }, + { + "id": "T1078", + "name": "Valid Accounts" + }, + { + "id": "T1570", + "name": "Lateral Tool Transfer" + } + ], + "recommended": true, + "time": 1755070340426, + "dst": { + "type": "device", + "ipaddr": null, + "hostname": null, + "role": "victim", + "endpoint": "server", + "username": null, + "device": { + "oid": 17550703405, + "macaddr": "0E:C9:8B:2C:62:F3", + "name": "pc2.i.rx.tours", + "ipaddrs": [ + "109.248.151.179" + ] + } + }, + "id": 17550703402, + "url": "https://envio1206.duckdns.org/extrahop/#/detections/detail/17550703402/?from=1755070340&until=1755070340&interval_type=DT", + "risk_score": 65, + "recommended_factors": [ + "top_offender" + ], + "additional_participants": [], + "categories_ids": [ + "sec", + "sec.lateral", + "sec.attack" + ], + "properties": {}, + "type": "New SMB Executable File Transfer Activity", + "description": "pc2.i.rx.tours received an executable file. This is the first time in several weeks ExtraHop observed this activity. Check unexpected files for malware.\nExample of a suspicious transferred file path. View more in investigation steps\n\nADMIN$\\xxFDMxx.exe\n", + "src": { + "type": "device", + "ipaddr": "109.248.151.179", + "hostname": null, + "role": "offender", + "endpoint": "client", + "username": null, + "device": { + "oid": 17550703400, + "macaddr": "0E:86:1F:88:60:E9", + "name": "pc3.i.rx.tours" + } + }, + "title": "New SMB Executable File Transfer Activity" +} +``` + +## Sample queries + +```sql title="Total Detections" +_sourceCategory=Labs/extraHoop +| json "id", "time", "url", "src.username", "risk_score", "mitre_techniques[*].name", "dst.device.name", "dst.device.macaddr", "dst.device.ipaddrs.[*]", "dst.ipaddr", "type", "title", "description", "recommended_factors", "categories_ids", "dst.hostname", "dst.role" as id, time, url, src_username, risk_score, mitre_techniques, dst_device_name, dst_device_mac_address, dst_device_ip_list, dst_device_ip_2, type, title, description, recommended_factors, categories_ids, dst_hostname, dst_role nodrop + +| extract field=mitre_techniques "\"?(?[\w\s\-&.,]*)\"?[,\n\]]" multi nodrop +| extract field=dst_device_ip_list "\"?(?[\w\s\-&.,]*)\"?[,\n\]]" nodrop +| if (isBlank(dst_device_ip_1), dst_device_ip_2, dst_device_ip_1) as dst_device_ip + +| where techniques matches "*" + +| count by id, time, url, src_username +| count +``` + +## Setup + +### Source configuration + +Follow the below steps to configure the Hosted Collector to receive Extrahop RevealX 360 events: + +1. In the Sumo Logic portal, create a new [Hosted Collector](/docs/send-data/hosted-collectors/configure-hosted-collector/) or use an existing one. Then add an [HTTP Logs and Metrics Source](/docs/send-data/hosted-collectors/http-source/logs-metrics/#configure-an-httplogs-and-metrics-source). +2. Configure **Source Category** in the HTTP source - for example, `webhook/extrahop-revealx` - for the Extrahop RevealX 360 integration. +3. Copy and save the endpoint URL of the source. + +### Vendor configuration + +Configure the webhook integration in Extrahop RevealX 360 to send events to the Sumo Logic HTTP source. Once configured, it will be triggered each time the events occur within your Extrahop RevealX 360 account. + +To configure the Extrahop RevealX 360 webhook, refer to the [Extrahop RevealX 360 Documentation](https://docs.extrahop.com/current/detections-create-notification-rule/). + +### Installing the Extrahop RevealX 360 app + +import AppInstall2 from '../../reuse/apps/app-install-v2.md'; + + + +## Viewing Extrahop RevealX 360 dashboards​ + +import ViewDashboards from '../../reuse/apps/view-dashboards.md'; + + + +### Security + +The **ExtraHop RevealX 360 - Security** dashboard provides a comprehensive overview of network detection activities and the overall security posture of your environment. It offers insights into total detections, average risk scores, and the distribution of techniques over time, allowing teams to quickly identify unusual patterns and potential areas of concern. + +This dashboard helps security teams monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. It also highlights detections linked to high-risk or embargoed geolocations, offering valuable context for prioritizing investigations. + +By consolidating these insights into a unified view, the dashboard enhances threat detection, supports more informed response actions, and strengthens defenses against evolving network-based attacks.
Extrahop-RevealX-360-Security + +## Create monitors for Extrahop RevealX 360 app + +import CreateMonitors from '../../reuse/apps/create-monitors.md'; + + + +### Extrahop RevealX 360 alerts + +| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | +|:--|:--|:--|:--| +| `Extrahop RevealX 360 - Destination Devices from Embargoed Geo Locations` | This alert is fired when events originating from embargoed locations are detected, ensuring adherence to security restrictions and protocols. | Critical | Count > 0 | +| `Extrahop RevealX 360 - Critical Detections` | This alert is fired when detections are identified with a risk score greater than 70, signaling high-severity threats that require immediate investigation and remediation. | Critical | Count > 0 | + +## Upgrade/Downgrade the Extrahop RevealX 360 app (Optional) + +import AppUpdate from '../../reuse/apps/app-update.md'; + + + +## Uninstalling the Extrahop RevealX 360 app (Optional) + +import AppUninstall from '../../reuse/apps/app-uninstall.md'; + + \ No newline at end of file diff --git a/sidebars.ts b/sidebars.ts index 85f9af31ae..afce08ddc1 100644 --- a/sidebars.ts +++ b/sidebars.ts @@ -2687,6 +2687,7 @@ integrations: [ 'integrations/webhooks/bugsnag', 'integrations/webhooks/configcat', 'integrations/webhooks/emnify', + 'integrations/webhooks/extrahop-revealx-360', 'integrations/webhooks/firefly', 'integrations/webhooks/flagsmith', 'integrations/webhooks/grafana-oncall', diff --git a/static/img/send-data/extrahop-revealx-360-icon.png b/static/img/send-data/extrahop-revealx-360-icon.png new file mode 100644 index 0000000000000000000000000000000000000000..31ef71404ad9a88fb6d73ee69baa3599aaed5d5a GIT binary patch literal 13766 zcmeIYWmH_xvNueC1a}X?HQ1noLxMXY0fOt`Ft}R?9^4%g+}+)RySqz};I7Z+{Lj7j ztoQx&tmo_9YxQ*R?yj!x>gukl-=5%43X*8ZZ;@eOV9=zc#6H8oys8As(THz=U-Ep# zbQl;^c{5SbPtu~Ik|x#DU5vU2bOIy$v`-@ zfW@|i*;$xOOAtSO&C~p|ZbJ(tb-!(&fq%9!G1iV(ZobTkT0CmeL;*XyUy3D>D2La@H$U>ju_n}GEbWgh`; zo9^-8VNLbZB;Ivz%P&6Vo}~I$HtpJL0`HaxMh=nHk0MtGipwR;o|(UwrH@6D{0{#9 zx#!aZJvd9!e9o*sJfGhF(a}q}H8)}_g@1y>&FkpvJV7VevYO_K*$I>1H?4g{zeEj3 zPrtX^xR``LvzvL#>~Q)7cl8bKCsOryoHY|0QZ4we9ai;jjUD!5 z2s*wPh~FbI-*$euz{2Uqu8>T{0&n=jQ?5%fMTcfnBn81Mk)KD>ND)=ODG;lrsOj_C zVzqAZmsQ@3|u$W1vzbRWIY{`eB@nusg zH(0?49r32IT~pyVtX!eNNe1YI#G3|6YRK_E{pGLK-m8YI7^116c#I@euoM%x2jbYi z8R;ZhLq_kwv3Vtgqx%ii%Xs>>8B5q-x951%^Tq@=Oi!wu&IQ}WuisCulSu^WS892T zO_0soqa0|b1!YtpwFb`ex{e&JG0rY_0uDFMHFg9Je=tVyBQ>^k21N0URy^t^+v78m z8I>9L9^oE#LCQsZu>_ccKgPH3Jp`#CNK2uVii}2=QkcT~r|D;=_vx|pKO)%!E2ArY zCqx=P?B#m=G*>DqSebG$2RpLWd|&t=DBmLLnUkAqoV)W2KZ{mXGh6jnt>WL}18gxZE%{)1i2!%j} zjMCcD5NPI+A`R}#rkH>0h6*`8m4P|>t3Ec-VxvDur zxl%3am&=#SSNrDZ=cLT5$Nyw2m9b6Ejq)tIq@5~llHvpeM+DD7()!tAOqjIs1LFn@ z_0kM3linr=Br?d=B{?N}u~va)SsB?EEu3ak%}2nathy#E#w#ZJ23Y!RqnRrk@if1q zt&)ryI?h73i5V@5sEcw`U<6KjaR&D)~ zjZwWsJ&U82{o~fo5v{$2&4F#5jiUYPmRDLySGY0AB;%6Y<;I=q!t~N*cW)=@*tPu} z1B6iau8glNFQ%9-nD%et#n|Fd%5lqZ(_r9s%+7g>VnSH~Xti$P+9#tSW6U~l6(^jT zE~P5vymPf*cgMT$8ErO(Kf_%B1_cqF9_Kp54PoGX1H?8UBsOhm6u=j!sf@^}U zqhX_Gs2$}=gRv)@AG9waZkZfo>{sDJngoBSg@N*BsZAm z1mW}K^S@(=*%#S6F=P~P$STEz&-%3a{+#!`j`;(AHpo=dw6)wt|2lI`oGYXt#2)`yV@tU@ z_fHv(w5-ODupb0?!Vk1JDR%j(An|w2k6OP^`8LdxR z4YId0Xj5oE(6sT^@rH?+!KDi~73@W4=5gNBEAjy;@m6kC>h-r1_-)K+nqjr^R-Vr- zH}}Mg-|M(kHB}O<>7bywCl|?$a1P;e@BC%6@+!;SJnd+0ZLSKgJo9A>iv!dH)tRiz zA9v}?1x=tMq`AqZwXt$5kiGT1P`P5o@%&Tu<1D%#i79`d(A-JZc0>v~8+sg=GR*$% zeR5@TV{%LiKSm%a)Z)~f_abIfu}MQ-vnc!zsk&>dTlLMK_KHr!$KIS?cST6L%N)4n z?^S<4U0Lc6-f3ID!;AS0UoRoo0Q;Re_2a6NU4c=OC;vy;N!Pmbu)n2$1HBv{FFyrp zN^ZWsMj0j$WT|yf*cWi?zn%yle3jtc+Sz3HWWF^$Vu3UZ)lzI(aTImg+#6m>0a@cM z-PyR0lXRv{G$lI^9uut;Jq=&gwP-`NC65r6ti3U>*RDi6x^^SBB7~d>gmVR1ybaE> zuL{m5XVQPBhm7V59C)#KKK-iOaxPirZYg&?-6Zq!uD+H(I`De$&U>2dq) ztERWZbIYu2nQ-%a&!Xqr9g_Ryq-*Kp43EUisEdk?n7?`Pqxu=gs9R{LQn&0+Yh^HR zVkJ{hVV;&=!!Q%Uyb<93oR>cm==)kJ%?ttSMp4Z%;2jebhO^!KE>Y*k*`DN^CqGR2 z_qz*am`pR6Zg&`mjqWHuk9cAMX9g6kbhK8*o7nUO^e1_xH0ic8cL$W%LKZ!Tdyw|j z_e+b!PAMS1_+g|bZ7eSj!vK^KVc=iAg?SB>UI9ty74d(UC0^0P!2PQp76vBJ3YwBO|E2 zskOs<%UnmG0?9^7-5v%8pXMdKlKxD60*pUnrmW_mCNIZlXl=!!53x2dVsWvuc^L;r zz=aPeS{XU$le<`1Lhbon1S$X3gAXXbRD&qV|JB98LXc8T{u8;VwVe?;n1z*vl~M?q zoSa<14r0vrSxn;JP?Ci|q%)w%9X98m5<>dvjvV+*!nSmb6_O4I| zeHUh^J=H&h{MR^QM)rnwW;PCH)==`7arF(X9UTNIDPI`<_w&y@jaVP`PyqC@^8b*;KVtq@Eg)whWC75B@0k#? zeu_>ju#NA`#1xf*98j`b*ZZC{W#$Mp@u|_6n6M%r5D|T(un4IsLzL~YH4zbCQINw6z*4dkegCIbEbLnl zlli5z3sCR(4HGk}|IJGVD?)A#F9uO6QtU)|A@TbbBnSSd2dokmIc123C$`Q%qlrN( z|LK7l^!62&`qX~R$qQGYjxq-AU;O+&Od$sKWvXWQ5y1Yd2`kC+pC0g;5+B6yYwoC< z|Cvot9|Z0nVoWYr%F6s{x^@45&E|s`E%CoslaGZNC0-(g1Og@nP*Jka|I-8Uf0y!q zy(_5nl(Ny?k7t9Rqd`#HMX&R!=Pqrc9&FuVi`(94MQV6K^4~Ens@NVb*{8)Fto8i4QXBhF9rST7C-He7s16vOv z71?WTJXmJR51UB*T`ZGkV?RGahuC`MbSD~sZS?f}pez2g@ny96-)yW+Y_ay`tw zS}*+kFv*XdDxEIck!0C=y91po*N3Ls_Uus+N|qROB=x|~J>MOa9o-+dIk!DtX)cnl zJQmhOd|qm6yCK0j%H zlbh~l&V5wBx$~&yisq>ov6R7$%&}ma)o|KNrW>{(L%lhGi5K;Fvl#*1j{ABg2ud|e z^IIPgx<5Rc2YleJP{$*sbPsrPmeesol7|wZgzKcPTUggm_s92d;KNYERdLWm{mzqY zdx)0fHKBV>OSY2Sd)YC34s#`YSrI~Z_CsueWHeHPK})M%_f~h&BWSNA6v0b2qKaVG zZ=qZ>YDdWyrM990sQvd1XA8`AOB+t}Mg*&U$Y4C^#(nG;g*|B7qZ9WaQI2*(vu6$n%Z=QRW}2($6s}H=`NWTKoD6}M$0iOU|%X&D2dOMznd3SOhVbW-zrt()z`Fsl|hSqls zb56>k3p!~w0y?}5UbNgy@PQbKI=yy>DA@}A`H{n_>;33hMmEkCRam#;R;1}Tt)e+` z>o}{uYb6Bw5r3AKWc>DeOcdi5CQS$Sk4QD5m^eh!vclil($8yFex}gbeuOvA{cbO> ziO+m|fktQ_qjE#Q<1BrhpZfCQe6(pd-F>7D14~cuRY3(b+_#xR$u>d9&CGexs_ynr zn`+-$IRBB&4AlW%96@>qUA7U<%@M%Ok=VMqg6g6<&Ln4W%c~Eow};oo2AAgSr$snl zaAhH-?t4a%U&>j>Euh7=z&ZBD80xB07imxKsZ^%r*v`WkKw9l`rB6B76KnXBE#-9f zMxg3CcThUxi?LKH!hBavV}=+;0u~Y4ucqVHMc`=IIffiYm6ZiC>5&P!3si5(w!aV4 zmA=vu&dEp+q~n;K$as?N&mdQfY5e?IYxV&bFY0gIs@G8{$H>XA8b_>bkG1ks#jAu}Kj+mMi7toR95?%k8hfe}sb@yWgXg=^YDw+iayZ-p zhuMu1B9AKwMIWiaaVqOznIrtxgOah=LsFUHyyDtQmqJH;4IFXCr!_&QOm5I(p9PLQ zXO#6PKa@#%?zE~uD%=OfRq@eAeHl;1l65S=QqI=kjK;Q zF6n)xgbF5pN;hdof51;-P^8IZAnQUWom(c$Nk1Y|i^9mbV8$}^eB(J-@ zmLt=(iFUmq#bAmEL>aEvuAS?=!Hbmt9u@-PdHzx)Kgh*z_iAy%@H;`!Nl9OG3-yGwY|PnWTT z{YFI$xIwC1J?`I*Dhl0FSCHzyS3Mu%P!zF|QSban0vM!~Qv!WN9WeK-Zz^z+IViqM zo5J(!OD+(gtnz=(Io6=&pRI65WK3xfXeW6qX>>jNh{n|Z!%@H1J-p7B0b%*C82&y3 zHG3B-$4!qY-3hXqItH`4Rn0W^VMDR)ur-sbPx=0SmYL8BiijxbTW7Ys{Gd=9lT^$t zF_5pS!uUs0T!^N|w0RB!&4w~7CFQdvVei+GSsi!ghUcgI7+FvY=P$|$4fAOF!P@CF ziFs+sxo#UPolZ$Ma8ydOkyuaD+?b|87pZ)RRVvxCuI+EU9J~}6Gg0%LJ7d9LX#Vkh z2yUWaWIdg@y0+j@=Q?dD-yQlo35B8?3m7sFS9h2IrDc~I3OMlajY(J5 zomN4F_`JrK(gA!3ov_4jU%fHa$4J7W@Kn_(^oNa$-!o9cL8Raf^rBe0h>Q?MK#L-N z`SiY|*xPI6h{Ji&RT~-0qAc}m-yzq_&Wfs9w!a~T1-WO-cVlrTCRhxH%fC3&13NUT zl`~XA^&*WjFui7YXW14QD69JVyeQZqHMgnVl=QMl{>Vvr&PToYgvLF4JNo{cnR%A4 zSXvH^$uX0Lo9=#%H#;A9a|NyJ;5|-6Shm1s z#Dp$Ya+#g!$H+B<1yb68vIIoH9q`#M;bR(eMip#1@jdqgMSrZM=!Cz{-vV~=pNT(=sG+a}pH|c3Nu5MwS$1Ohg*;oQ$OBB;a!}f|L>a>L zIce3+?dkbfocNLo{)7+ej@}Y*yZ#A4Ct1j^F3cCFT(}|No7p@_K%_rdzmwMw7TFd^ zv7GCfZ%(U9uUVB|)o2w8;W9`?lWj7L5UjO%|LS0xX{`OYRe^U;jQaf`>Gv?dvryKF zd5QEz);#{psW0|Ms7b{pe`a*ttt4^vB4bv|RV*`4gGRnfKjcp6ManO~tC7k+0o>Z-ESxI4 zz~i~sb7#Wn6}N}{24vvQ%>#I_6uiDtr4p(0!)b3*%k@grSA1eFJFwzc)3PP^DJ4l> zVxK>b)>p7m;ms*lr@IM%KRJQ*z2CVyGNjZowh^CXiMbuOTziZT#!fqhgv<5E;xvR{1fyV9eoX%&Z8cIK`Ufhxf4w}f%2ia+xU6?K|jQo|3StKG6l zyeM8wF?HtZI|_>$PqVCYB9`ZRs=ta&nYEk$dbxO$Kl>OQEm_x`I6@nhCOE2%X%0>u z@VX4VLDvK%^LDoiE0nGSr5sv=sTEvn9yXFnf*XyG+}}E->Y+zb z15dB~Jh%0Gs$X~Ah|wD$h^r~3Gh6l7_!N>739hC<8~Ya-Ytf_0&d#wG8?2X^ zc}55}=UR6t3>tFFF2P@&@zhg0Zb6C%d=eBPcoMw*rNP6n#oz5URRmLe`;G&MJl4JprHp zaW8+*%c@>&@VuFMtnp~w&~Vb->g|~OWcpWzaHR-6iUKqz zVv30vXMa#qSL!&1(h01$`bUD6U4Q2c%Nb_1?-A0LzUOD9!Nk?XuNKJ?;*@Yyh^qnm zD1VbzM8;{Cjl=>-er1)<1P7Q*!cEXmaLg73g_0^OJz6wQ!Lw&}D2Wx%(c9aJi#c^; zN#aWE)rvr-UP~DLScy2O$aSG93+54h?-#dGJb*iQQAZ&fa6>AYM98DL`0HoZs1<`r zpCV1V_tPz-d(`}Ofh=U5S6T> zP>gx_i#-oG<~j`uY*wO}2q@K>6zr@*e}4M%$v`*>#UW;B z;tt_why_MrN;p|%15Fb$j4Ief>my8s#SBHlUU}G}Z{adAu`|h}AJn$~7ZSzgi zU2|7`G7$~&^T9+cGAU2_GLQ?-Ig)I|Ngp|ge0+JeETrjgttJIh?F1E0RE~u;WS0=9 ziStv#4+b5^*#k@>{wRm!51LVN?r$igl-TCaiY!IaW^Ay=eNdW8FcBwYe#G^)hw(Du z-*PzjUFiZYP>ily`;U8D#fwpy=SIaqT(JG z8L-qx-}0{o;+qLpE{f8@3FfymJwVWlnZgL!GB@Ehwgd`G5hyMALT85s*~?ARNY8D> z7*zEmpGfQs6(St{QNPqi8&I*kZ4POF{3M2d_5}aRM|}PxDLSjMw^XfqS5)q)Tt-OW zQxz?iI%7>?jk^RAWtDf`_}q97qwz|^qioVZygTSc+1c7Nd#ohh8V8zUcdzzW2+DjPoqSCfzU1FO zFmN;7!*_~*QVA6qSxkj2Yy)LwKP0VqbanHC=Ui)KeUb zJs;D`A&W?v6)XFgL@B>3Q@FRLt9xhFex?$;>|8Bc>&{`1cEy(zk}o@Lh57gWImH$X zp&ISVoSa>ts64UO8k1#|bF%DJn36sA3-TCL z`r7pAkz4*&pXW1R@Ddi9CKm>U&VY!Szec%D?#>KHcm-mR>F}Av1fub$u?lE$jjGd1 zqKXCRjA4j6y7FB7u2H~LCpt1}3-0?d{_9u4$-RL`;~hb4udo+WN-9(%DaoR;WtU;K zDJ3ZMI?rT*Qw59YBb+1mC+OWF-z`#y34+(opXB|hbgoytb5e}&-%$Ggnb*!N{wS`9 zW?u#%kPwB?G(WZkz3?6!xJgj~UxE}H{*!8RkM^*0}Gq_4}Y%7vf4aIFF$rr4A z24MQ<=MWq^PZ$_1?iU>OZ<=E<4Ht1>69AL)!`H!t3~n64B1OOMr1jH#^&K9```5?s z@N`V@-$f(gVbzx?FuyPQuQk?-wh7VLw>H@Kjy5E?FRW5mnH&vOPhPw7KThXbSi&y? z*nr{nin}%cBjX~|aan-26xg1#SZ<}?)HvaR2fM&4wx<5g!HGnih zJro5mW7B|e)oxP40|+F-9s#V&zH29~J0d$TAGMusvp1p+Km)HM*KYnsilV3{dhU6u&_@Ws!EZ?DtK7l zg^c2^CZEjN{{)=UD`0jYroIM@DDTVZuLqQSO9bB|U+|PG09V_aQ{Md`q8b=|x$Wmy zOj-mz{vpwanRb8FGmQHg>^`8+IzBeCk0#;Iw-wS(mQjHG+|d#Dc225#BujINsJ5iLoBJpokVieDt?8_go9?ZE&;@M7#E zmuDm9#4=|!?B2=%qk!buyJbuuHnxwxkZ4m80pA~1E&BNQ^iYn`Vrvt7r4ir|`0Jah2m=tEuScruVWjY&U+B%mt&!APG!E5#O;F^r zO&1zX0g>B#RSHd$G{?6p3u_L*#t=ARggeYq8WCzI&0o_zUVpN_?oG<~D^6f>1;U`e zA}Gw9^j{*`h(fZ~AXz6`79}-rmSaXZsT`ZPqGcC=15+J$t0E$C5E##F=emDyBhe+gQ3W=-~*DW6%+yo^ga+)oh6R!(& z>z?Fqz2zP{Q9wh?xZHDkaJu}*04(xHqOj2zFj>F!5F*x+EQ`=&_+emvFBYppA82kHz0b06I>YYx-to?7rL0c_Ir)96P7 zP#bP80*ON;nJhK4P2oZXU3WjJ9Q*r&j~#iEB#yB;?pSQS39Pcmsa@V%j|gNQV-bS{ z+uR$5bFeG(CE=0FuDfY*tuh|cjfq>87Zb7sJL+emZP3S*v*$>jBm-cH!_1gTpU!~e zVBO1?mi-PLlUs=drY{gk71QE|8vqe8cC4_49Ry7CfnYnd11G%h4)JE^;` z`5@d4e28{3k8L`vl+{N|;Dk18$G4LAGrr?-2EHBO2lT#a41Ce2t*D%~&>}p%&)NPK zL7N>2WR_+18_4c}c3><3!HSOTwY}<)+j|IZJ;FPi4`!sZH#?+&8vkVa<0Vt4H3aYZ#$Z?CD`ZY9O&Ljr zd=o*bFw9~!=y*-QG(09vyMGDF>P+wF zayZ5fMwo>HUgOeRsDZF{cy;W6S_S}Y)g)>ICa|I8%wZ`zPMTKv4ZX(%|CLq!dO&<9 zZOi57zO^ghYl8`l5 z?{`6!52%Q?{#&URyj~#xb%F`iYyPT>0pz!>TyDU*mwg>oFMP8GCv3rywv*diRN7cr z#+Em^AWPv(BBW&)#)Ul3C2v3d_{adUG1)*l92m7jJRpy~fj+)v9^CB$Q zju-+=A)9wL%i0bRryZ{9VbQAAlx`~EiRsVaR`Iu{{xi4VQcG!sGHF_*7Y?4V10v$8 z$mXv;_v!g0vO%Rvn&tTp7GjoW%S7HVHkR#8kSefk3g$el;Y4R%+f)08%8(eET##NK z&{9~e^S0(oGDQ<`-^=!_xpV0tBV(~20M^PlLhwpW*ebO&DKjk|xPHr)Om*#txgHZ= zZ{mAAOOSag$(Q*zti0JU{F%ant05CiZen%(dlk2qH5(-oxb9Tv)Nr}4$!xo^S}!$w zg**V)A|e)F75C18#Ljv?;Lj(s7f{W^Bgl%RVvUq%!dxPMQnSoIw0=*=xR$QSd`jLB z>$viK?st=taslD6A;hM0wRow^IZOFdU!dcIdXJw)_bX@kXtM_l;fHeT_vb^+R@8n> z{l3*Ru4H$vF_ASVD{)_S)cGVn^yEYuu=1G2)wm4hqlzRDbIss=)f%5=aAhmf*`S@p zlA;Z<1RRa{jics?gy23HaWAloKE z+S&TmC`4uuU%bt)Oh3xIv1MIsds-RZxX$()vQh}M`6jLh6puc8?ms`5P(fnZTt|!S z!#SBN`zW0-2U==|xq!_$p30C3G}xX5jGl1!3;t9H14NcHW&FqHjB6tbDiK>XD- zc4ZMnpnWh=AI#K)3hOD!xdY!+eWR&I37G}Xl_%(}LVQ2^dwf8c%bH$12aFrVa z#MY4s$a=!Kh`zd$+O_=gW0VR_@ibX-3u`#V4!@{hC{&bH64*Ppv0*0L)F|r#pseKO zUD!R%hYB1WGP>Hv_>7K#i-5EUp}Txr=JBO!{k(%aPN=a7pIV9G!!GjYW6;-cM0MH8 zwsAO{8WbxTuAyl>L|-xQ9UAezgfhZ=-leG#pYgQHI8F2%A$yO4Qs~e6MKJ`G6Tc!J z%y3=^4F{B*bAuaLfd2@)rW{;xLVGG~aWv0ZF!&_jZSl`uS}gg!+hkDPiBS|{D@|x8 ziwXQu>qpe;wCvP#3AuTYTiMZ=?y+B9DCuD)+nJ1PA-e*;eU#eb(VefjAKyB7UW`i$ zY2QRQ%j?M92NXt zWV{FM@D7$w(=_LJlwZN5dyCH&(|NK!`lRbrmhXIG;X-{bwx+1Ko&2ep)iHxV)ix%e z`Q{)yL8LmA?zLi_KgOtDo`DEoNP2>T^_koVjhR&VZOMX*#C#Rvs{9J=k-*NLLrs{l zwDXx}cZf+&(n)hJa6M84K@EP`GD{qbJ|xbiKNx37CrhEk`D1o7T4ne#$!G0U5J#{< zKd#A8Q1P*2)X-_5LLUa|Y0}Jve&1*mr6jU$dCjJog!AqYZZ_rxXiXwvVfsALeUj{h zHlIp>Adl8o*Z5L>8mta*9Xfq~WZv$f>1T(0gVHrhR|kJX^ppG`GBcEiU1{9>unZMP zue)oCs7zeNe-L!Pan(o8rI+p-LWy8GNt1o>rqP1f2l!5^mw~_h zGjMB*ZBaRK-Gy?<*k51P<)oyDqc%nEA+6ZR8k2%ZO4ei~slH@aNs*b*gtinSUuc}= z=F?&z{;x#@{dh_;Lykw?6vUtp_3*%2JQyh~dIneJY3&(H?(vXsZfvr_b?F(pr#{oL z|B{jHi;U|2k&(yvXm3yqt^C>GV|7rbEoMA>ar zXj)UALYn!~z_u|EMa9W(IKbBM=)DWI?xmGW)C2yZkU3*9R^w9rJ?IQ zI7bYf;*~{`aZHE#M=fG*sMgizSZ~=rjmET^;dGY`q$)t+--WBMAZaR{YzUpTGCA_j9bKl5vYzom_yPk|d5{Ow0Q8C6S8*%V1xEk4qzb*eOga0=@xFOTg4Q7>2=y!zy9%*p}u~HGe@BatEpxGt> literal 0 HcmV?d00001 From 7f79e3984a9cb93866cb4d8cdc4a5d0e135acd55 Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Wed, 20 Aug 2025 11:00:25 +0530 Subject: [PATCH 02/11] Update docs/integrations/webhooks/extrahop-revealx-360.md Co-authored-by: Kim (Sumo Logic) <56411016+kimsauce@users.noreply.github.com> --- docs/integrations/webhooks/extrahop-revealx-360.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/integrations/webhooks/extrahop-revealx-360.md b/docs/integrations/webhooks/extrahop-revealx-360.md index cc05f52559..1573afe226 100644 --- a/docs/integrations/webhooks/extrahop-revealx-360.md +++ b/docs/integrations/webhooks/extrahop-revealx-360.md @@ -94,7 +94,7 @@ The Sumo Logic app for Extrahop RevealX 360 ingests [detection events](https://d ## Sample queries ```sql title="Total Detections" -_sourceCategory=Labs/extraHoop +_sourceCategory=Labs/extraHop | json "id", "time", "url", "src.username", "risk_score", "mitre_techniques[*].name", "dst.device.name", "dst.device.macaddr", "dst.device.ipaddrs.[*]", "dst.ipaddr", "type", "title", "description", "recommended_factors", "categories_ids", "dst.hostname", "dst.role" as id, time, url, src_username, risk_score, mitre_techniques, dst_device_name, dst_device_mac_address, dst_device_ip_list, dst_device_ip_2, type, title, description, recommended_factors, categories_ids, dst_hostname, dst_role nodrop | extract field=mitre_techniques "\"?(?[\w\s\-&.,]*)\"?[,\n\]]" multi nodrop From e3e3c5b1bc39bd6614b23496599a620deb117442 Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Wed, 20 Aug 2025 13:16:58 +0530 Subject: [PATCH 03/11] Update 2025-08-20-apps.md --- blog-service/2025-08-20-apps.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog-service/2025-08-20-apps.md b/blog-service/2025-08-20-apps.md index 007eabacd2..2f71883d46 100644 --- a/blog-service/2025-08-20-apps.md +++ b/blog-service/2025-08-20-apps.md @@ -1,5 +1,5 @@ --- -title: Extrahop RevealX 360 (Apps) +title: ExtraHop RevealX 360 (Apps) image: https://help.sumologic.com/img/reuse/rss-image.jpg keywords: - apps From 653b06ef1cec51b043e655ebe087049ce518c858 Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Wed, 20 Aug 2025 13:17:28 +0530 Subject: [PATCH 04/11] Update 2025-08-20-apps.md --- blog-service/2025-08-20-apps.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/blog-service/2025-08-20-apps.md b/blog-service/2025-08-20-apps.md index 2f71883d46..b8f12de400 100644 --- a/blog-service/2025-08-20-apps.md +++ b/blog-service/2025-08-20-apps.md @@ -9,4 +9,4 @@ hide_table_of_contents: true import useBaseUrl from '@docusaurus/useBaseUrl'; -We're excited to introduce the new Extrahop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360). +We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360). From bb0b7d2d4e0727a1606e499ca28674b95226f8b0 Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Wed, 20 Aug 2025 13:19:24 +0530 Subject: [PATCH 05/11] Update extrahop-revealx-360.md --- .../webhooks/extrahop-revealx-360.md | 40 +++++++++---------- 1 file changed, 20 insertions(+), 20 deletions(-) diff --git a/docs/integrations/webhooks/extrahop-revealx-360.md b/docs/integrations/webhooks/extrahop-revealx-360.md index 1573afe226..59c8acf94f 100644 --- a/docs/integrations/webhooks/extrahop-revealx-360.md +++ b/docs/integrations/webhooks/extrahop-revealx-360.md @@ -1,27 +1,27 @@ --- id: extrahop-revealx-360 -title: Extrahop RevealX 360 -sidebar_label: Extrahop RevealX 360 -description: The Extrahop RevealX 360 app for Sumo Logic provides security analysts with critical visibility into your Extrahop RevealX 360 environment. +title: ExtraHop RevealX 360 +sidebar_label: ExtraHop RevealX 360 +description: The ExtraHop RevealX 360 app for Sumo Logic provides security analysts with critical visibility into your ExtraHop RevealX 360 environment. --- import useBaseUrl from '@docusaurus/useBaseUrl'; extrahop-revealx-360-icon -The Extrahop RevealX 360 app offers powerful network detection and response capabilities, providing organisations with in-depth visibility into security threats throughout their environment. By centralizing detection data such as total detections, average risk scores, MITRE attack techniques, and destination device activity, this app allows security teams to quickly identify, prioritize, and investigate suspicious activities. +The ExtraHop RevealX 360 app offers powerful network detection and response capabilities, providing organisations with in-depth visibility into security threats throughout their environment. By centralizing detection data such as total detections, average risk scores, MITRE attack techniques, and destination device activity, this app allows security teams to quickly identify, prioritize, and investigate suspicious activities. By leveraging real-time metrics and contextual threat information, the app highlights patterns of malicious behavior, high-risk destinations, and devices originating from embargoed locations. This insight helps teams monitor evolving risks, identify vulnerable assets, and understand the tactics and techniques targeting their networks. -With its comprehensive detection summaries, geographical breakdowns, and detailed device-level insights, the Extrahop RevealX 360 app empowers organizations to respond effectively to emerging threats. By maintaining a clear view of their security posture, teams can act swiftly, reduce dwell time, and strengthen defenses to protect critical systems and data. +With its comprehensive detection summaries, geographical breakdowns, and detailed device-level insights, the ExtraHop RevealX 360 app empowers organizations to respond effectively to emerging threats. By maintaining a clear view of their security posture, teams can act swiftly, reduce dwell time, and strengthen defenses to protect critical systems and data. :::info -This app includes [built-in monitors](#extrahop-revealx-360-alerts). For details on creating custom monitors, refer to [Create monitors for Extrahop RevealX 360 app](#create-monitors-for-extrahop-revealx-360-app). +This app includes [built-in monitors](#extrahop-revealx-360-alerts). For details on creating custom monitors, refer to [Create monitors for ExtraHop RevealX 360 app](#create-monitors-for-extrahop-revealx-360-app). ::: ## Log types -The Sumo Logic app for Extrahop RevealX 360 ingests [detection events](https://docs.extrahop.com/current/detections-create-notification-rule/) via a webhook. +The Sumo Logic app for ExtraHop RevealX 360 ingests [detection events](https://docs.extrahop.com/current/detections-create-notification-rule/) via a webhook. ## Sample log messages @@ -111,25 +111,25 @@ _sourceCategory=Labs/extraHop ### Source configuration -Follow the below steps to configure the Hosted Collector to receive Extrahop RevealX 360 events: +Follow the below steps to configure the Hosted Collector to receive ExtraHop RevealX 360 events: 1. In the Sumo Logic portal, create a new [Hosted Collector](/docs/send-data/hosted-collectors/configure-hosted-collector/) or use an existing one. Then add an [HTTP Logs and Metrics Source](/docs/send-data/hosted-collectors/http-source/logs-metrics/#configure-an-httplogs-and-metrics-source). -2. Configure **Source Category** in the HTTP source - for example, `webhook/extrahop-revealx` - for the Extrahop RevealX 360 integration. +2. Configure **Source Category** in the HTTP source - for example, `webhook/extrahop-revealx` - for the ExtraHop RevealX 360 integration. 3. Copy and save the endpoint URL of the source. ### Vendor configuration -Configure the webhook integration in Extrahop RevealX 360 to send events to the Sumo Logic HTTP source. Once configured, it will be triggered each time the events occur within your Extrahop RevealX 360 account. +Configure the webhook integration in ExtraHop RevealX 360 to send events to the Sumo Logic HTTP source. Once configured, it will be triggered each time the events occur within your Extrahop RevealX 360 account. -To configure the Extrahop RevealX 360 webhook, refer to the [Extrahop RevealX 360 Documentation](https://docs.extrahop.com/current/detections-create-notification-rule/). +To configure the ExtraHop RevealX 360 webhook, refer to the [ExtraHop RevealX 360 Documentation](https://docs.extrahop.com/current/detections-create-notification-rule/). -### Installing the Extrahop RevealX 360 app +### Installing the ExtraHop RevealX 360 app import AppInstall2 from '../../reuse/apps/app-install-v2.md'; -## Viewing Extrahop RevealX 360 dashboards​ +## Viewing ExtraHop RevealX 360 dashboards​ import ViewDashboards from '../../reuse/apps/view-dashboards.md'; @@ -143,27 +143,27 @@ This dashboard helps security teams monitor detection trends, track changes in r By consolidating these insights into a unified view, the dashboard enhances threat detection, supports more informed response actions, and strengthens defenses against evolving network-based attacks.
Extrahop-RevealX-360-Security -## Create monitors for Extrahop RevealX 360 app +## Create monitors for ExtraHop RevealX 360 app import CreateMonitors from '../../reuse/apps/create-monitors.md'; -### Extrahop RevealX 360 alerts +### ExtraHop RevealX 360 alerts | Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | |:--|:--|:--|:--| -| `Extrahop RevealX 360 - Destination Devices from Embargoed Geo Locations` | This alert is fired when events originating from embargoed locations are detected, ensuring adherence to security restrictions and protocols. | Critical | Count > 0 | -| `Extrahop RevealX 360 - Critical Detections` | This alert is fired when detections are identified with a risk score greater than 70, signaling high-severity threats that require immediate investigation and remediation. | Critical | Count > 0 | +| `ExtraHop RevealX 360 - Destination Devices from Embargoed Geo Locations` | This alert is fired when events originating from embargoed locations are detected, ensuring adherence to security restrictions and protocols. | Critical | Count > 0 | +| `ExtraHop RevealX 360 - Critical Detections` | This alert is fired when detections are identified with a risk score greater than 70, signaling high-severity threats that require immediate investigation and remediation. | Critical | Count > 0 | -## Upgrade/Downgrade the Extrahop RevealX 360 app (Optional) +## Upgrade/Downgrade the ExtraHop RevealX 360 app (Optional) import AppUpdate from '../../reuse/apps/app-update.md'; -## Uninstalling the Extrahop RevealX 360 app (Optional) +## Uninstalling the ExtraHop RevealX 360 app (Optional) import AppUninstall from '../../reuse/apps/app-uninstall.md'; - \ No newline at end of file + From 8d89262a91aae26705707ef99d5bb4ae4ce6c060 Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Wed, 20 Aug 2025 13:20:57 +0530 Subject: [PATCH 06/11] Update docs/integrations/product-list/product-list-a-l.md --- docs/integrations/product-list/product-list-a-l.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/integrations/product-list/product-list-a-l.md b/docs/integrations/product-list/product-list-a-l.md index 6c66f268a8..1664a4db41 100644 --- a/docs/integrations/product-list/product-list-a-l.md +++ b/docs/integrations/product-list/product-list-a-l.md @@ -219,7 +219,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [ | Thumbnail icon | [ESET](https://www.eset.com/us/) | Cloud SIEM integration: [ESET](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/ced86de0-64e4-4e7c-ae25-fb5b3dff3cb8.md) | | Thumbnail icon | [Exabeam](https://www.exabeam.com/) | Cloud SIEM integration: [Exabeam](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/9d2d799d-2d6c-4894-a46f-0cce00641bcb.md) | | Thumbnail icon | [Exploit Database](https://www.exploit-db.com/) | Automation integration: [Exploit Database](/docs/platform-services/automation-service/app-central/integrations/exploit-database/) | -| Thumbnail icon | [ExtraHop](https://www.extrahop.com/) | App:
- [Extrahop RevealX 360](/docs/integrations/webhooks/extrahop-revealx-360)
- Cloud SIEM integration: [Extrahop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md)
Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) | +| Thumbnail icon | [ExtraHop](https://www.extrahop.com/) | App:
- [ExtraHop RevealX 360](/docs/integrations/webhooks/extrahop-revealx-360)
- Cloud SIEM integration: [ExtraHop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md)
Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) | ## F From 120caa2dde657ab72446c8808731a78aa05b1b7a Mon Sep 17 00:00:00 2001 From: Jagadisha V <129049263+JV0812@users.noreply.github.com> Date: Wed, 20 Aug 2025 13:24:03 +0530 Subject: [PATCH 07/11] Update docs/integrations/product-list/product-list-a-l.md --- docs/integrations/product-list/product-list-a-l.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/integrations/product-list/product-list-a-l.md b/docs/integrations/product-list/product-list-a-l.md index 1664a4db41..8dc6da1e76 100644 --- a/docs/integrations/product-list/product-list-a-l.md +++ b/docs/integrations/product-list/product-list-a-l.md @@ -219,7 +219,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [ | Thumbnail icon | [ESET](https://www.eset.com/us/) | Cloud SIEM integration: [ESET](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/ced86de0-64e4-4e7c-ae25-fb5b3dff3cb8.md) | | Thumbnail icon | [Exabeam](https://www.exabeam.com/) | Cloud SIEM integration: [Exabeam](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/9d2d799d-2d6c-4894-a46f-0cce00641bcb.md) | | Thumbnail icon | [Exploit Database](https://www.exploit-db.com/) | Automation integration: [Exploit Database](/docs/platform-services/automation-service/app-central/integrations/exploit-database/) | -| Thumbnail icon | [ExtraHop](https://www.extrahop.com/) | App:
- [ExtraHop RevealX 360](/docs/integrations/webhooks/extrahop-revealx-360)
- Cloud SIEM integration: [ExtraHop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md)
Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) | +| Thumbnail icon | [ExtraHop](https://www.extrahop.com/) | App: [ExtraHop RevealX 360](/docs/integrations/webhooks/extrahop-revealx-360)
- Cloud SIEM integration: [ExtraHop](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/a8b03e2e-7497-4104-874d-cafd03aeb4c1.md)
Community app: [Sumo Logic for ExtraHop Reveal(x) 360](https://github.com/SumoLogic/sumologic-content/tree/master/ExtraHop%20Reveal(x)%20360) | ## F From 005ee1d1cf4f7eec1a69a948f06106f2311f6946 Mon Sep 17 00:00:00 2001 From: Kim Pohas Date: Wed, 20 Aug 2025 09:43:21 -0700 Subject: [PATCH 08/11] fix frontmatter --- blog-service/2025-08-20-apps.md | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/blog-service/2025-08-20-apps.md b/blog-service/2025-08-20-apps.md index 6f0d245299..57dca6569e 100644 --- a/blog-service/2025-08-20-apps.md +++ b/blog-service/2025-08-20-apps.md @@ -1,16 +1,11 @@ - +--- title: ExtraHop RevealX 360 (Apps) image: https://help.sumologic.com/img/reuse/rss-image.jpg keywords: - apps - extrahop-revealx-360 -title: Vectra (Apps) -image: https://help.sumologic.com/img/reuse/rss-image.jpg -keywords: - - apps - - vectra hide_table_of_contents: true - +--- import useBaseUrl from '@docusaurus/useBaseUrl'; From 11c275da3dae505047558ec1a09bab82d037b60e Mon Sep 17 00:00:00 2001 From: Kim Pohas Date: Wed, 20 Aug 2025 09:44:25 -0700 Subject: [PATCH 09/11] one more fix --- blog-service/2025-08-20-apps.md | 2 -- 1 file changed, 2 deletions(-) diff --git a/blog-service/2025-08-20-apps.md b/blog-service/2025-08-20-apps.md index 57dca6569e..b8f12de400 100644 --- a/blog-service/2025-08-20-apps.md +++ b/blog-service/2025-08-20-apps.md @@ -10,5 +10,3 @@ hide_table_of_contents: true import useBaseUrl from '@docusaurus/useBaseUrl'; We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360). - -We're excited to introduce the new Vectra app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud [Vectra source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source/) to collect the detections from the Vectra platform. It provides security analysts with visibility into security threats detected across networks, cloud environments, and endpoints. [Learn more](/docs/integrations/saas-cloud/vectra/). From 037d55d6d0545c982eca5e4cf67b38398bc58e69 Mon Sep 17 00:00:00 2001 From: Kim Pohas Date: Wed, 20 Aug 2025 09:46:25 -0700 Subject: [PATCH 10/11] resolve rn conflict --- blog-service/2025-08-20-apps-extrahop.md | 12 ++++++++++++ blog-service/2025-08-20-apps.md | 6 +++--- 2 files changed, 15 insertions(+), 3 deletions(-) create mode 100644 blog-service/2025-08-20-apps-extrahop.md diff --git a/blog-service/2025-08-20-apps-extrahop.md b/blog-service/2025-08-20-apps-extrahop.md new file mode 100644 index 0000000000..b8f12de400 --- /dev/null +++ b/blog-service/2025-08-20-apps-extrahop.md @@ -0,0 +1,12 @@ +--- +title: ExtraHop RevealX 360 (Apps) +image: https://help.sumologic.com/img/reuse/rss-image.jpg +keywords: + - apps + - extrahop-revealx-360 +hide_table_of_contents: true +--- + +import useBaseUrl from '@docusaurus/useBaseUrl'; + +We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360). diff --git a/blog-service/2025-08-20-apps.md b/blog-service/2025-08-20-apps.md index b8f12de400..598be04afd 100644 --- a/blog-service/2025-08-20-apps.md +++ b/blog-service/2025-08-20-apps.md @@ -1,12 +1,12 @@ --- -title: ExtraHop RevealX 360 (Apps) +title: Vectra (Apps) image: https://help.sumologic.com/img/reuse/rss-image.jpg keywords: - apps - - extrahop-revealx-360 + - vectra hide_table_of_contents: true --- import useBaseUrl from '@docusaurus/useBaseUrl'; -We're excited to introduce the new ExtraHop RevealX 360 app for Sumo Logic, which enables you to gain real-time visibility into your security hub findings data. This app can help security teams to monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. [Learn more](/docs/integrations/webhooks/extrahop-revealx-360). +We're excited to introduce the new Vectra app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud [Vectra source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/vectra-source/) to collect the detections from the Vectra platform. It provides security analysts with visibility into security threats detected across networks, cloud environments, and endpoints. [Learn more](/docs/integrations/saas-cloud/vectra/). From cddae184bd0e5623cb65de1edb973f25449d300a Mon Sep 17 00:00:00 2001 From: Kim Pohas Date: Wed, 20 Aug 2025 09:55:29 -0700 Subject: [PATCH 11/11] crop logo --- .../webhooks/extrahop-revealx-360.md | 12 ++++++------ .../send-data/extrahop-revealx-360-icon.png | Bin 13766 -> 12109 bytes 2 files changed, 6 insertions(+), 6 deletions(-) diff --git a/docs/integrations/webhooks/extrahop-revealx-360.md b/docs/integrations/webhooks/extrahop-revealx-360.md index 59c8acf94f..d038688e35 100644 --- a/docs/integrations/webhooks/extrahop-revealx-360.md +++ b/docs/integrations/webhooks/extrahop-revealx-360.md @@ -7,7 +7,7 @@ description: The ExtraHop RevealX 360 app for Sumo Logic provides security analy import useBaseUrl from '@docusaurus/useBaseUrl'; -extrahop-revealx-360-icon +extrahop-revealx-360-icon The ExtraHop RevealX 360 app offers powerful network detection and response capabilities, providing organisations with in-depth visibility into security threats throughout their environment. By centralizing detection data such as total detections, average risk scores, MITRE attack techniques, and destination device activity, this app allows security teams to quickly identify, prioritize, and investigate suspicious activities. @@ -107,7 +107,7 @@ _sourceCategory=Labs/extraHop | count ``` -## Setup +## Setup ### Source configuration @@ -137,9 +137,9 @@ import ViewDashboards from '../../reuse/apps/view-dashboards.md'; ### Security -The **ExtraHop RevealX 360 - Security** dashboard provides a comprehensive overview of network detection activities and the overall security posture of your environment. It offers insights into total detections, average risk scores, and the distribution of techniques over time, allowing teams to quickly identify unusual patterns and potential areas of concern. +The **ExtraHop RevealX 360 - Security** dashboard provides a comprehensive overview of network detection activities and the overall security posture of your environment. It offers insights into total detections, average risk scores, and the distribution of techniques over time, allowing teams to quickly identify unusual patterns and potential areas of concern. -This dashboard helps security teams monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. It also highlights detections linked to high-risk or embargoed geolocations, offering valuable context for prioritizing investigations. +This dashboard helps security teams monitor detection trends, track changes in risk levels, and gain insights into the most frequently observed MITRE techniques, top destination devices, and key targets on the network. It also highlights detections linked to high-risk or embargoed geolocations, offering valuable context for prioritizing investigations. By consolidating these insights into a unified view, the dashboard enhances threat detection, supports more informed response actions, and strengthens defenses against evolving network-based attacks.
Extrahop-RevealX-360-Security @@ -151,9 +151,9 @@ import CreateMonitors from '../../reuse/apps/create-monitors.md'; ### ExtraHop RevealX 360 alerts -| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | +| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition | |:--|:--|:--|:--| -| `ExtraHop RevealX 360 - Destination Devices from Embargoed Geo Locations` | This alert is fired when events originating from embargoed locations are detected, ensuring adherence to security restrictions and protocols. | Critical | Count > 0 | +| `ExtraHop RevealX 360 - Destination Devices from Embargoed Geo Locations` | This alert is fired when events originating from embargoed locations are detected, ensuring adherence to security restrictions and protocols. | Critical | Count > 0 | | `ExtraHop RevealX 360 - Critical Detections` | This alert is fired when detections are identified with a risk score greater than 70, signaling high-severity threats that require immediate investigation and remediation. | Critical | Count > 0 | ## Upgrade/Downgrade the ExtraHop RevealX 360 app (Optional) diff --git a/static/img/send-data/extrahop-revealx-360-icon.png b/static/img/send-data/extrahop-revealx-360-icon.png index 31ef71404ad9a88fb6d73ee69baa3599aaed5d5a..8e2dc56d7d1e7abded7218776fda9751af1ba811 100644 GIT binary patch delta 8484 zcmch7cQjnz*Egg07DO8@LX;tl-Xn;pA$li<34$1mmaEqwiQZeZXcGicqL(ljC3=nM zAtHKxCg1h@J+W;*{!Fj)kQHaNo{l;NDKjY!4i1IJ zqlfx9IJnMOT923z`@8h|X~9QM3v$gA2NMmLwl)qwR!EFPfJ=*mhox|_Ck`$%4#7V( z4$fm-mj9;paryqG1H!?HgyZ1~|EKtWo9MoTJG?;H{+*k`{eKPdAF{+DN(mrSFciSSVdvC%sQeU(yPHjfqW^T# z7utGarTpYp4~XF>UjcCpsZo-h3XwlMi^3f7G+T3g>q&@fcSr$%sn7tyJcC7^me z-4Xn0C4%Kcx?|2~bip0rf8NB59+Vz_1l(MeTwngtJ?dizZg*Txn!A;0B;GAEwhsJe zLA>2|b8UY0XGC#(3Aiz=9Z_g*TF(HSpN{0ne-o^I2B|U>k9aB}3*sZ*X9{4Vbe*kx zQadc;eEN2t43w2g%=48<_6e-Mm6Q+u`~xzf_Y5XBxMKaH7zw}AwN$`*0%hAZ zF;Qkv!s%7@d0ihn*CXi2k4VwSDZ332x#i#5Z(aspyec*JqAh3GaP|iXAiH zcg0WUJ!1tQJ$!ji>{^GTb5)d<`|4c7^~>41TBw@MdlIP5#qsVpP2tvOT3qn4N34<{ zVn>--=jzsCaKOH@xc5(!qZJ^MJwy2&42?+|r&r?T!E~fpdYgXg1N)Z-9?z%?H7MKWk0LDR-)iFk5^QK2gH-kqK4J5b~Sr9*eVCh`i%r~_uo6cohNV-HKp z?rkMH-E>iFpI0^S>6c`^jG@7#6+EXmaYkP3HVonTUmZ=c2sIly&<~xgrCLjbl^UuVz*?`cO!eNuHS5eQRq6D2&}gh@JCyvVXpK^A#=tTv%0t+ zGcq*&cPf?wPZqSyyl(5eOwrbGw+pUgz4DY>Jsx_zRvg8&yAKhK8 zQUkdDYYt2e@iWoTfU~vK&!28HRGO*S#PmI-tEE~bw(u=ZWDo#~E0E);HzvZ$u7m4< zW)c%baW5x5$4!PkRcDa|WcZLH5e4%QaNbbW`zSiH?M{>bjd+S zV;7&e%5?hzM*~m_)u-Xn`G8Stg3;~khht(S&Zz=A`Xtb6(LurSeXVwm?rFI`Ffd5hCWNYo(A=s9mg;ZU zMO?1SyV5a!ce)#RTH||wUYu*$6}!j`fYY(>b{Af!Ot~~Q-u!^$ouqhQR8-v9EJno` zHVPFW`@SuFztt-Yd3BgAl)5qMe<668d(mjK^>xhH20NSorI^2vne|o5kX%G|Sxl^A^%1?bR2$eBt}7=xY6^Wy+Q#IE zn%RcaKmKKmS#-*ra-u>x;w>^-2iT$#3|IwU?BBU0))^FT3s~3Iuc)0d6}y4+o`Zm! zw~WXZcip)^OZ?97W5*)Bf;(849?yC0&Kg#>91M)_XBW+#C?=w;Tt9u&Qn?HFTj}IL z`Je1jbl?OI+lJ<<0gnOcBh`IGsrGz?6YNL}h^Z$b7g?#x<@Fr@JU^kv+C z@3Z3{X9**5aq;wFd!nI6Rp&(-#i|7zXF6czj6-URS3jk|4@ zqjfw?9o#izjT;vk1YkM+oP-;360`kjq+Mwd->U?tTm(fSD6BW1Vg};f`0Ii!lIw|ynaqUVM8tl ztI?SvSHg#YI)HYnD72MmVlrM^lWJoOchMDeWjt z<;io%_L?+Zw=)+VH&N3Z_*m$ba#_<`#42>ptN@L z)6T-c7tOo%F{)D^2)9EuNEEsdQFDB4gYAQMsw{HYl(t^M1w9cx7><>6;Eqk}*y@;^ zkc3og!KhsVus*Ml`5wis<)}&9u0?dzuQ+sz67-q+-DTtqb+HAMypxG~Cg<;-hDA9p z8|WuBbkUBTPj^K#k0dn(sFWoW$6_6_lcWWkmRI16(wwQ;5Z z%HY)Lvj`ZEA1pHJ%?n|Rs4uj%3~qW8U&aX*5;F^$dZP54M$g9Nu-J{O@#EXcSjmA8 zRDsE_66_qbsT|hWh9h4tE2CNa2~f|!0yx&2ObPG?6-w!D&Bu3bwIRedRdT_@G3o?l zD%C9qF&|Yv+Th@MawgF@b^jq?xQJK0MtThjHQbI{U>s2>88u}s%t|4Dy(z-wSe``R z9?kTK)yg4RRY4G8>9kYH*&AoYMY&-vCD7? zrOYNr?Tfc}wS`voPRgsA9w+lx{Gmnn12Yb(>2zZz9CnD+nvjT_V}&wuXmf(XIbSlW zS2taoM~E#=9P@VI*5m|9EeH=6$c(oD6`=jNohGgPUBw)l_nLOHipj&IAYp>*?jgBF z(e;zw8zu>~t|L%hnVLK%idMfPQH7-x_5Osd8n@YzuP+b*_-Vo-Qckk|VsT%PqZ=5X zgRi{h3W4Vjt;KI%ln(`s29XIkR(1tWq z9@}u)eX|9Z$861rptO@ktZzCkD8z-y0A% zsDh3GO7x?6g>xq{j+F&HU?->@cBn4U@r<5AgspyOBgcPun&7@OW|7=TYlP-*Rr^!K z$%2n$pJx-=*^l!ZV$9tvUg?O$c|f)K^{O}_?LZCQW2s+_{$nC2j?G$pEe&&*kKwZ} zwL>*`#5_9a$!U~`?NC17;*dxQ&ZvSALC<_IogkN}o$~!0t32^qKz6&==ErkcLNS!z z@r+{}Bg4RJGJ*3uG3>uA&bkfR!R<#cup7UG*vU&u9*SzV>t-YavjtSbG0$zR@;uz& zN6VBIMMU&F;>U^dak%5X@Y_GS{9m6`y%p4!cIeHg%a=}KYyUH<&Thz?=bj(T%HO<1NZxoS4JJ?)$5YZ;+JZ4j``EZllw$dir zPsYAXJTDRwIA>Rg-YIvgonYG_l-LvDXcplH-<2g)omYedj>b6bJA~VQ>?i1Y`GEBG z5FJ<>@o7swBtxA0wgFDAQF0`*uHjCx4dQAa*pT12SBQopK(gg|`Ge$6Q`nvL+tDhT z_oqvpXgG*Pa9C=UTv(;~An0t=Y&0qT^TTkEm%})jGXWkEC3J_t>E=s(|LdS|XNmid zqSSGIp3DNy!uI+FR1fi7J0_MQy`Zm7CE=!c9X@lCP7$lkds{miS7XV;3b6<80*3*Z zSenAvF?-lq(@vGM1Yh_clBK?6#uG@E`mFzKRez`NP`EgKZ$wyJx{igBO}Fkq!jnW~ z9BswAUcEZ;5gu8Xgjl>_aGcKcV!&*quy7qqiv&PO1^)Rn3)A(0aqn3GA8yYT7!C;vzC6I3~vVg+}E%IENS6;&Ru0W|ezW zjfaLf5N36AHR@&1v-{cQ;aeRyBQB-Slw&Gg+>8GokR7Bf=y*eF)Tk-G+!GIp+PeI5u~%+U{ixt5}nYo&HfM~VZ|mQlXWm_(da8f3NoA8CKb1Q=vCHRrTI27@eJSFEUWWKmD`6RYDG%*7o6;rH`Z0k z;%=yzap64;Tjp{j?k73K|HK`cB+6d^n`aI8+QZv0W};6U@Q}2H7N*B+_>TIF2p+wq zVc_N$J0Y%XHa{a33QANjBswKh=uw5}F1J@RwaWil)>q5O@DIhf#|qV(0Gzu*W>4gZ zrDUZwxY1m41rAA9EM~vq5LuhHXO4VquW|Di*$9-ojWN=0GJ_MTY?agHreRrc@zUHM zQ8iC8N3$o2L?#?qXq*jPToO-M)E0LPURN*{D%2126Tom)y@k)VW2B=35(y#J=LI9C z3GKSF!UkQXAR3-bc(+hY0W)RiYk4fQr*x8ep29CUd398>(W; zOfO<`$d(0Sh8JmZfBvRf*W+E9gvoiMzHJNJA~l{VZ(}c+7yzF#XMp|dx;Wayqft3$NX3H*jQ@XKyLr*7r_y!JXT){rSpHfC??JhXq`1hV+Oh%$uOB$P3OKkFqe}j^#WL8US3CPm>7FBiqJ|F{ zu0Ve-uQnRgXG=ct4~Lf@$(wwtmtpLf=y6j$DA%8DB5}s2mymXG{Q~#A)hNQv-FV-5 z|8LdNM0J>&Ft`uQ@9mc#XUl7u zdnECkj$5IlPCLmZjKx!xa)6V&pl%L`xE83hh&3{pUNtMZt#SN#|((FdXuWNyMG|2VUMW zigT9jX71J1xvwLm3xllz1^VYeYD+CXAx=P>knl4N^O43nQ)G5gj)QTf;B2A+bo_t_ zI0&k)?mmh|X_bkCF$PSwmUnLpYN=Ae3!X@^_GPH~Z$;+%}R8HvA?c-GffRFaPcGF3sNU<-uSTr2A=Fd`B7;r-)LxEa*X&So!Y& zV#S7|ho#>W(5WTkq$UFg1WtWI)UTFvfcOVrMg^+4FAj#!<@U%F$oa9Y8xdxXx*(qn z0RalbD5?aEbwDs~HWPCUN#kgW4Z|0tnt9hvz`Y31L*I4Mea>11M#ZM@>bXU5UKS!| zDcp&pb$y6=-=(m&FB=7`3b|H7fODc{Ju23ia( z8SW;cStjD#E^HYJv=LDy?Pb_xi<%BS|PW?dT=&@yTWqI-=8pHXJ#Wh&N@lx*Ze zRl&iIbu6LWd;WqsyaclQcY4Za0e{&!??6a=6Q&s3*2$N)cR(qq2d>6RN?ZsDR(B9B z_ooj2UI8Anr_fLR(&#I}g%?(Iq$Jk~BqK3#{sI9~UfUBDs#icjw&_~P_z zyYb%I6z?GNZ_>|C4+?>tefeDm3O^jOI*oy7Cd8(xlE{nsMyHyIwj(A!LVHHnAJvkz z1he*o>A6<^B!^&9Ue}e&WoP+S=o*G$R=w@)yQHgjX5@I|UYUU0E~(ijk)N8&fJad{ zq5LV)?p%Xzi<9oa190QPccwFV&#>y_KVo(71_ZS(SiEQ^#zj1Z0Hi5kmg< zeY>zN@~YEMei78zI>z!fhr3rsU0xT|Z`(1A5LQj!S`|RUfe_qu#9+v}t#Aol&r6?% z`dcheTg_I>)QgSg^XlgOyd|;H@+q2o6PwC8wGLBXf_AfS4NLGDn1r&qmWoRWdqaN4 z%9VdW5&E=(?Eu1Mvp+ItI|RE*nNN%1{ukUDCX8@)V>80rNlA@*Qv_<-&+g$i3xcVu z+LJ=z)VXOJU<2Z%ik-2dSkw72?zHsd&0hW^#j}_9KaCYO|Ms&jq&!JVmb9sbeT*j< z*yM6vlpB8^3fm4ji-1eQQbr5aWwj}PL<(ha>vqUOf&dy`yc)7^jA{IoljHO6@7;yb zYY{hkt#_nBQ`iIQZUyQv*+^lVJe~|*V42u4z2rkAO$Q6MtyF!ldVD=CGhSx9G~yH_ zceH-`8W)eSTf&gXb+U2)l%cUys5878Za@BD86_PtBt}f5xr&FZohN(eB2_yZlucOCP0c!1KQzaMYi6*M@$d*i#EEAuy^K(g}Tr2Ahdw-g7OSuuhyjghlCrS>T~9|Y%g+`g={5tk4*R>)WZ$tw{U6l;Bb%C=7CJJ0mv zk1vT2J6-cy9a_@PH+B4UT2X7AjDE{6Gu|@Kz}R|7{c9Gr=$%gHaLl1cnw{-OU@#ut zsRqEu-411T{o_6}UvfXx<}M;Rb)5+cY6!qRf7zU&&ug(BP%8r6sH~qIKnkkDW3TU0%~B`w*4mp~_O$eh&!BU2$FHAsCQ9#Hb7no9z|i{!A~kw_3{+-Lwm3MvSKH zONf=Z`;V#B#d^n!M5canots?Nk}Z0xn|y21CFi#E%lGhpzNnQY5pjy}CE?;|x#Lxl zX$dzO3SV{E&w)#{H~HhL&PHaX26a{**&&yf@Uay0!Iu1vWPsU^<`&?A9Q!78lB9ho$Dg; zPf)u~J1=h32gB|<*(zxXuXuQosM$L3>&j{=<{na{b#=udzGga z>WMvfPs%(WuG*t<(?0;lnc!hgod*1Qx}?L#kfJV;?g!^Xc?b8R(Zd4xpX+)Mx7+!9 zgg1^xOzK9f>!4qqHuJelZf$Kk6du!E_8tX$7{_AR6-1qYU4HL0#tB$d^1GJ3Ljfn0OkkfTv{E6A6{Cu@MQmk ze14`beUDmy!{OXEV7LQ{HX-OeX($>HR%*IKkB=Wr%B`ni8+W0pNuoL5DwS4JgchM+ z7w5FZqN$`D*jq!BT9@`aY_~b~dDjslB-mMS5KqtrKPGjKAL+iO|0`$^%ntP2;>z%9 z9ZfyJ2ZAT#lz76$n;WU8k0ipE2|`-ULjIY?ky_rnPUeQs!FWV41@|)I#x%=mY12c! z8!qT0Gc4xm)JptR-^4y-^ILi9StGWg?L1%?No#GiVc!;4O!?=#S2B zBq=Oa6|T>m@~>9q86nIsn|?ezRpYbh>j?aMo9O#j6h!#pXj#u+ zB8e7@|8kJv4xcQG+#NRBP+-Tf)AN-?~unF4` z-^_{OAAtHV@En`R3n%ysP?yqSxgGqvTipKyj0XRq38S*^80kN;<;8MSBu@9#{zBWq zT*Of*NJ!3mY>2Qhw+@!8qQhYEx4%%fD)p)2?1<&u$RL>G?|%?9RCOL!J+KM+FSj4U A;s5{u delta 10191 zcmcJVWmFtpx1bYTgIfr0!6mo`cL)g(ENBBEKm)`-g*1@Ov z-g{?$%>0;p*LQoZ>QhyH>YTlgYRXl}NCSS?rh;NhunX#tn0g=1;4m$$?Bycx9M%D2vV=n z(EJqeNa<O2oDdiU@n1D)aQP5us|u%? z)&u_~&TAP)^8Zk$5Dzy-wp1LQ6O;;kik4^opBiZYM;GAVsmy;v7vNu_{+pEfZ|DO2 zYuNu^GxL8dgY}YDIkxBSbdd9CkhA@~&vn&%hcVe0q5hz1uxVVLO6-&Df36OgJhd?G z4SW??rUGu)eID*y)%D8T@0&b#^OBarINN^XC>(&-p8??EuKs2x3s{;ni#p_J`b}Fu zqi5a7-AhVGh5UgCft~jCCb~#B$E4NRH%aIacb|&UL?bwr-T|*QWr8N%4l4VWz@86R z+;=G8!vd=f5)ZeNBKYZwnbMspHf>ki(76f|Xu3o1E*+_SscC0QFT&iz^?v!$&2hVH z``x8Jut>dj%amrrBhXJD_ZI~%A{weLad#dka(mLfY?2bw z_ShS{vy%>#{7jEe0!Iy-+jj=;*xtrbOIZRKuNFS$H2&$MGKyGGqTd|AC5pNGyBP)j zmGJ&jj5FOTBVc_*{N~_j-ZJZ=JKXt5Bhw3s8sJDD0|)a!E}V3o(tQgLet&a(gMt)+ z6{$_|EIi;W#i5sMIZ+?F>$2n^FR+^%C+sv=x|X#R48bFxhLOLrVOvLSfH+^Ga&*LcYRWmYrvNddD0oK?Ot)<7i_5*@a>iGqqK;)^ zMe@XKg*ycyB}|mpGh|5F7?(hW5P|F2u)s}-kfU2|EVjng%RF!aPN@p62h<+z&Zq>q z1^*tx6;e1s-v5QhwwAtzn1*QIa%>vLzFoKMqA%cfvX+=r^V0gyPZC!d{{)6Fydk&@ zdRXZql~aDcq2$np&SBn3m1klu`c2?MUglr4*-Y|-m`l4LdqOlE#DU*m^SF$FJLht$ zaqgI+`W262edlQ{{fR5**$+Fm;+$U-PYY5kp2Nqaaju?Z7$W?ZszH;Hh3MN<2D;h= z_{^%#6uCN%2o-oq3&v3sgBg%Dow^$zY1^$ z&{waJHL|#^s7}KlSiL86&{w!+sxTd#n4Q6i%iDC}xSACAc zUyYo6uXV=DmD&v9Y}|@XoXwx|))u+a(d$?cj0A^tu=Vb8vF*Jq=YDZ{+bO%wj16)( z_UM2Q&TKcpgz`8(O$6$q<9G{8ym%O@<^E$g*)=C!m^UbLXjahL3E~91?%ZdnvYgc~ z#}R2Ez(yz&#{kc%Fp`C%-H{(EC8;~RCj!*EtTA8TXGw?A`=mPO1uIRR7iz*e|J0j5UX4-Ivhv%(yLk9=Ae& zgpsGM8fZKq<*k=WGx~O7R1?r{hx=t67T+O$m89f#hVA%;%&b(e(|+$U z8P+ET-WSt(XR)wr(3mi4hw3r6&4>YOE+?I+Om*Lu2fIYAE~!(A3`!B+Ct3w04+*S# zwGJpG^&iVI(hVX6H|}JLRQ_y2Z>lOC#kZy(e=#C9BlJTcA5r4L9%<<2;s{e?gY)$9k4sny(hPnnR$^nUd}_p%^OUUG8YZ z_M6UFCTNEI0<-?gz3M=vs4=?S2*rga2$P&}76 zhtJ+&vvquRHmUQBtoLU@T|Sf{-eaNX>Bf5Xw^y3!1Vcv`hh5jUb{hYnvBY86j?LY# zVs9_UN_+)VN}BSyD|bO*NVvUaI_{PXr@yw^xFjVZL|#-ly1?gLTuVa`TGvb3OL9hF$X9{4r@Q<}$s_b7T6Z-IS_f zw&_&MMh-uT@`%!utfW8XU0aBK#|}&sM)i>9*PN7=^BCh5PBk`6sBaGqcdh>b6~2D9 zPC=vY!NCuiN31_cf->?b3W)!F#1Lug z(3lKclrXcrRy0t#RHQ{w+xt3Vqrh^^kpT9)Q$So;EjFT1L1 z8#w%g6#d9QUA`Vmu(ZTuFc1Do`vf(BQ(psz(QLMgZa?#Kx(hj zduU%OqX%N76acPAeZ-^|y}R2cft%R{HcvTP4=kv0Q-+(bzmK=L9{2EttZWnAO+?wW zA_8v(2*{il>OSlzp)l2f-e-~MS^p(d%y-X_G>u@LcTO@h&&D)47RkrpC71J-R7Sfx zW1r$GefEo+N-MyCgs!sxQZIX~OJplr`ZI+kQ@Z>z55V?y1kPfOo-v>)2NCrIu;X$Rc%ft)vOecy-CY{uobJZRjo&W(^1g=MDWqx5c@i3a6+BQ-~ zZLc>ykV0lteq#2HI@hq+i=VP}zpQzQHjM3U%BqLQ{loVJ*(ELF2|uiD<0a70{tkLZ zu~1l3R47Zk@Rvk*W^+FY?dAUZwW>*|)GyIAo4MZkmW=Am+Ev9>y*BYMKGSq;h^ zMwJGo>+PSu=2rMh^Lt`)zR&#X??09=c}{7_3z7T%cDB1jh>2`Tv;DJ^boj=F-voH! z?#z-_&)QCYk|X1B+zR&^9gLrL2@9JUyqGo0THG7`Vzu5Ot^|u;y>wh;_Fw7M*0)U{ zDnIqqioz0Q4_Lyv&?cVwj)gVNBd-?#pmulI6w4MT%BZK$Tz!C-nN z-u>81}c1rr1M;AKN-;hR8 zm1Gqoixl&g&Ab^!C=Bi9(sa5fVVC?KYj-7RVvV`JXDNF zej0R7-`w2P7*;}Ht>-q=HsCf=}Pgl7#hwwsgJm536A@v^<~aum|dX8HD8kq zKKFOcaGc`S_#dHfnRvg|7))MGes7&BCrgV+hqfAIf_a#_A~nvqY%UW-@ja(vCN#)$ z5^>_?#H-ojkZ?*(K;zE3X$pxayHi7^WbUQoXIUAS9z1zMx!pP`$P}`i`PY@G{mOhd zhVoEBY36{0jgkSvx$}A&>7c)q@+qW(`itMc<&4_0Si;m9GJ*RmR?nDu_zz{sx{#`b zm9gf9O*PLSidI7~^~q~p*3#DfS${ApykGK`B06g3(iH_l`HJh2n>qij66C{{q0ZG zrEx?KDtfXxy+=2|^yqw1L-#zNDxafD7H=MynF2Us67CjR@N`F?i>w6`TZvUIN;4sf z6?U-QLY|edMUZl5ZzAb!i58Wi(pn3L&kl?6R9I$Eo;k>{Xq!aeQ+zg4i*gRcdRG@~ zO2^}|IrKsDjSTVWJMm>%1lR zq?u4Q|6OzxLsB`dDR;UkwKLHX#b$`a%A3JCG(bcUQ>p$Dz;>)xg822Iu>zwr-V^#z z58SzTQ*MMY%yV@5!8unWW2Ob35J4!h%zGgdeRm^4-8APC@4Ji&$Rc`n<;or|8Ibm~ zDotQ(x~6Yd=UY0t+xF$6ozWcrXm?_15%sdmRzx7|_aA(*FuKw1?8(^$nyM2!gE3`R zd69?SKxc^gI(#qYmu4GBBk!6gMALLJH800ei!Ie_??(ZP7OdUmB}VIE%~>G}ju2_l z$JC;b@EJ~W_V+O!lRGoRQ9i*qRDhwdWn3_}NCuav0pF-Dqdb;Okl`4Pw6nY5`OjK4 zTwSsw^Y&2K*YWS)f1KQydNo~>#P><~u%)F#^-@x-t6FzhR-4m8!r=v$3%pu*WRi%^ z0&k$#2f|nAotCIR+rLxyVlw%j3e737GNaJ?|DOMlT_P!~j%{k`$(R^cF$Xjr7(a`D z9Yfn93wh8bn5(ajRB?n{SpV`pj^P&Vq%^Bh5aF(oB4g8387)7-3gQx)P^$#{qsHpW zPs`__MGU*Y72wdFN1qaWxIM$n;61IZH%K8ca$R<2okg_BB5&(^4KeO%uVbe5;M!<6 z#3AP&dXPV;xeJ01`Izo_1C^0jx?N+YmnqKe#q!$WgiREMVpR_y5`K6HBVh7=@&r%d z5xE{_IF~T+kq0+}L{$W-{z=&2#sLC)EOHlPfbr8WNa((=big1 z|5e~&xvcGaFR>-9?_<+$esuxJ!gL9x%kDt-f%4&+f#FLkkt_zW z1!fo#cOVgS?B34kiOMY~#Oh$$?2D=gsUbXi?eAf<^fP8GWy%IHY6}Wr6_M1f1z8x; zLU6=g(}mptIX1$E0;((XM?tR&pL@^T;|f0JBJ;gPKXTeWNju z_SMBzfiP}qL~t|wgV?LPTWDloB!x9_cQLEButyoLO_ReVc2Locf$6EEn#$XM4{p{= zP&`gHSR+mha54RUpLTbN{;Mj{_0RbhH#n9ugaxmPCo1^B@ zqv}!dwjectz13zFOxX_0nveFZxj>B3{utIBBI1Y|yNAZj%uT9G*#2;5Vn+x#TCgrZ z{2PD}zhEVRFcnrYb*m=&r)MeEh^Z18)m%z$L0i|H=msPb!~v9TlVDPoYv=ImPbU>7 zTZOMTh?rW-eQy8AH-nw)>ruJGC*Mk3|IPu(&(I}du&iBC{XR2p%z2RMzDJE|muIh9 zC~Ruueoo_0sA{dpAaQ#lU7CS#0xpM35vdSghDFZyTT>jd^D#+2?==74*RCbSe{)d1=;!CxOFQ-wFD0%0dXM$dV>+|o>L#L1UV+W6TKR3j zMBd8mr@u|lEmQ-CP;@;nC!eS-$iqih2^Y4 za!w4aOKVY<<3@PtoLjbH0p$g7-_#^rX-UcL2Pd+d`MZ1Hl~U^Aqd9;H7Uu1o4yA-w zhalr+ejrj7*Y=yKY313I?KHb1R`y+c2E|Hqsl;#s2KVo5nFqBoggkBrV5BimAAe6# z9IYY5{QPDRQO+D5K%n;W0G+yAEt!i3-YV(jAtoo6*J9I>4F3Tb)!(aL0V=m$n4ClG zgaUKMh(?9)NMmCj=~$QcYeUJUeMiDE%XEjJV|-ix1CW%xEYV=J%0uRL*pL}CzDhFk z+0~b-@oJtYTO6qSf~UlS%34w(Me|NCi*Tr4(8Bc9J*hprybQ-KhT25dEzkH`rsokE zK7T0PP4lFh2tcI$cCBs2V_%m=bWYL(xAq{D>Asb?3Z$4H-;7F{a<&uZqf$6UQz_H4 z+ZQcVGWGORs_-!HOLi8>Q#i-xdE#;RC2=Vqr*{Kecc@feV^M=7zXUeS<`7oqOCzI~ z-FGq)+LXK$o07Mx&L@;fwslXX+o5-9rw`GBDW;3IK>aW~Zpxcea2L7q%z$E zd{Cuqf}O+*ZTywkM%~Z)LeLd_*+3lBhtd@MxTdyZ^4i0TiHP3j23m(~cA`?*ls9Z( z0G{9y!C3&)7(->aqxO&oGlZ}K^@aUwE6QBjs^hksg{MsCLj%PN?N{66VS>cJLUZ|2 zcl^gitz+i#{Rd-#a*;UL`XA8lyaD=NOll5a@-DQhUQlkWKW zOeZ0_GkFEyf;Q<8D~h_sDUGw~H;^4jluDn`7`p2phhIgkmOZU8Wv&qBD}`BUmcwe= ziA=&aJf_IFcfpz66(+Txe|QNxghlXZ*SKcxn0Mc8o;Ohp3qpwL%IxQJIwlN7orQvt zFlfdBc~WM5C;!LrXXJ%n9Up8a`2!7HiHDi-UDEKNkr zzPqM^pe0ta?opfr4DWd^D?uo8CB;*2VK8fB_)?F%r9l>9V$i8zGuu8-B;cH`5ZntN zOr9$|@_o@l-KbS4NI$kodcXC}I67V>`dExU8wDoV#FhL7B#% zLfpVCf)8V!Pt|ey?v4dwZ@GbaJYv7&ykW`6PB3~}2e8l-pGr>dhj0=#{D-vI^(CAc zDxI3%hFJW1_ERl*h@ZqE8-~X{gOSm1S(i+LDQ+FBm$li4E?(8vEqp4*bMK5J!418R|8Hu1JE?@d+6>ix~|XKJ7UjLIF6HLl0itg?^v77Z__q z#S?22UOQ2Iwwn+7{l@B%y?J?s*iuxkQ3_6ck}I6lFAofF*fq4MV=DeMrD}$ETy-}0 zvspv)2kEdG#J+2_WU1RVNAnFV*!fnsH^92*sVh>f)h&+1ZG|24*-(oueE`7L?_V?H zPIc`b7hQX@lJMS8S6J?KZ(g)1m!MTbt=mu`mQ)fs-we@vgYj7wckW`t4aQkK1;#KN zF!D$|{<$WP?0e?^=Y(eje8b|>QM;6CQ&XpdQdE*qf4N{i`zhg%K@ZyZZ_(M-u`>`u z4gV3B6K-Ts5sR4@Lh=xk259I-S4RanVR{`zNmlm5e@k?>#(}(m~?6-A9WZBYD}Y zV6-mTX|}f@X}^Ey^!DHl0;9EBK5F~z6w6f5>JB#yX+IwrhVmQ%(vZ!37V`HW<5w0r zNj~gPG=#GCqWi6ytYH{#YQqb+G|Y26xg)H(N#ExPs0|H)2z)o|SH3Jc6QO2Pkjy#; z2~}?dAK80P%FnI816UQp)4VO0JR%zZ;76V}EEK6LYl!Zi+1s;IZR(Zxg1{?vc?V%v z|F)9Akcz3UDKQJ^3_1_Wh!VdpbYLG}sxc|pzvhKnSPJWun%(YTyglZ8?@Lyno9d82 zu&GD0lI0$rAxQQf_r|G-=v_D~lJ|9n4*98Io07{!?-2$t%9-}^v|k!WOf&gC+Wrjh zx%hBU>6rk3BZr88hI`unB`>tM(t$w#lmkat{>7Ha?1eS36!2n`MSD9=U7Witse>vm z_-kDNS)0qUOYa5b@2$$pw%&BFs&x_pjp1+#k(mav)XY~`Evth}=(_yDQ-2@dcXC7ZyrC${s5^m71X&B)YxpR2w0o z=z6N(6K0v0a?+9y8cLcFsOeV+cDZBe+vK^-TfibqF;xLGArQBR)ix`DO*Ln`l01qV zD!HaaLnq9GQ_G}>1-%_;V959+{`0S1aauChmd|X4Wu(wH>1I@U5AoCiji|(=I zcmK59*6L7PL0*5Z88&w4&$XPA5_QzBE-+*eA6;wtBbt^g6Mk!e6Q0zbM&=Jq zu-Uv{3?}}*h-#8ZOJ(-z&L|Bn4kgz@*UeJ+1}W|q+( zziEVj4U_WYFxCGvOkU%oeIap-s;7f@H6hs!xQRSX*L%gofB$UW&0a;&y?Fx8KpV}Y zq%4n;W;7S5Wqev1_+kJfRn?slJ~Xy=%R zAAF4uiCyX)#!8|ooa{1a>T%{kF52LAXbl+Q#vN7mQThbYvvwA29?{NYupod_C5aau zjr>cEjPCK`4|wr&$5EH<-}npg?``hC+#2w2*XX|{0`NaEsQ(2Kfd8R+{r?c*FO{KD XC?1z$Qos8X@S`ZJCQ~M5{N;ZEaX(Hv