Integration Use Cases
Get Alert
Retrieves an alert by ID.
Get Evidence
Retrieves the evidence for an investigation.
Get Investigation
Retrieves an investigation by ID.
Patch Investigation
Updates an investigation by ID.
Post Events
Writes a batch of `Event` objects to the SIEM configured with the token used for authentication.
Query Alerts
Queries alerts from the SIEM configured with the token used for authentication.
Query Events
Queries events from the SIEM configured with the token used for authentication.
Query Investigations
Queries investigations
Query Log Providers
Queries available log providers in the source SIEM