
Securonix Unified Defense SIEM CDF
Overview
The Securonix Unified Defense SIEM CDF for ThreatQ enables analysts to ingest statistical reports and identities from Securonix.
The integrations provides the following feeds:
- Securonix - Identities - pulls all users that interact with the IT infrastructure of the organization.
- Securonix - Incidents - pulls incidents from Securonix.
- Securonix - Top Threats - pulls top threat reports from Securonix.
- Securonix - Top Violations - pulls top violation reports from Securonix.
- Securonix - Top Violators - pulls top violators reports from Securonix.
- Securonix - Top Violators by User - pulls top violations reports by the user from Securonix.
The integration ingests the following system objects:
- Identities
- Incidents
- Reports