Security alert review

Network security alerts sorted and escalated

TelecomEngineeringRiskSplunk, ServiceNow, PagerDuty
How a run goes
The steps this agent takes, in order, and what each one leaves behind.
Reads the alert stream and the asset inventory

Triages security alerts from the network and the signaling layer against known patterns and the asset inventory

Correlates alerts and applies the triage rules

Groups related alerts into one case and drafts the first analysis with the affected elements

Opens the case or logs the closure

Escalates the cases that match an active threat and closes the noise with the reason logged

Works inSplunk, ServiceNow, PagerDuty

What it does

  • Triages security alerts from the network and the signaling layer against known patterns and the asset inventory
  • Groups related alerts into one case and drafts the first analysis with the affected elements
  • Escalates the cases that match an active threat and closes the noise with the reason logged

Connects to

Need it to work differently?

Every agent can be changed: the steps it takes, the systems it uses and who approves what.