Skip to content

Commit 6e98502

Browse files
committed
Sysdig Secure (apps)
1 parent 3655bfe commit 6e98502

File tree

6 files changed

+289
-1
lines changed

6 files changed

+289
-1
lines changed

blog-service/2025-05-12-apps.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
---
2+
title: Sysdig Secure (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- sysdig-secure
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
We're excited to introduce the new Sysdig Secure app for Sumo Logic. With this app, you can gain real-time insights into vulnerabilities, compliance, and threats, making it easier to understand risks, respond quickly, and maintain continuous security and compliance to protect your containerized environments. [Learn more](/docs/integrations/saas-cloud/sysdig-secure).

cid-redirects.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1632,6 +1632,7 @@
16321632
"/cid/6024": "/docs/integrations/saas-cloud/vmware-workspace-one",
16331633
"/cid/6025": "/docs/integrations/saas-cloud/cisco-vulnerability-management",
16341634
"/cid/6026": "/docs/integrations/saas-cloud/sumo-collection",
1635+
"/cid/6027": "/docs/integrations/saas-cloud/sysdig-secure",
16351636
"/cid/10112": "/docs/integrations/app-development/jfrog-xray",
16361637
"/cid/10113": "/docs/observability/root-cause-explorer",
16371638
"/cid/10116": "/docs/manage/fields",

docs/integrations/product-list/product-list-m-z.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -164,7 +164,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
164164
| <img src={useBaseUrl('img/sumo-square.png')} alt="Thumbnail icon" width="50"/> | [Sumo Logic](https://www.sumologic.com/) | Apps: <br/>- [Enterprise Audit - Cloud SIEM](/docs/integrations/sumo-apps/cse/) <br/>- [Flex](/docs/integrations/sumo-apps/flex/) <br/>- [Sumo Collection](/docs/integrations/saas-cloud/sumo-collection) <br/>- [Sumo Logic Audit](/docs/integrations/sumo-apps/audit/) <br/>- [Sumo Logic Data Volume](/docs/integrations/sumo-apps/data-volume/) <br/>- [Sumo Logic Enterprise Audit](/docs/integrations/sumo-apps/enterprise-audit/) (multiple apps) <br/>- [Sumo Logic Enterprise Search Audit](/docs/integrations/sumo-apps/enterprise-search-audit/) <br/>- [Sumo Logic Infrequent Data Tier](/docs/integrations/sumo-apps/infrequent-data-tier/) <br/>- [Sumo Logic Kickstart Data](/docs/integrations/sumo-apps/kickstart-data) <br/>- [Sumo Logic Log Analysis QuickStart](/docs/integrations/sumo-apps/log-analysis-quickstart/) <br/>- [Sumo Logic Security Analytics](/docs/integrations/sumo-apps/security-analytics/) <br/>Automation integrations: <br/>- [Automation Tools](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-automation-tools/)<br/>- [Basic Tools](/docs/platform-services/automation-service/app-central/integrations/basic-tools/) <br/>- [ESMTP](/docs/platform-services/automation-service/app-central/integrations/esmtp/) <br/>- [HTTP Tools](/docs/platform-services/automation-service/app-central/integrations/http-tools/) <br/>- [Incident Tools](/docs/platform-services/automation-service/app-central/integrations/incident-tools/) <br/>- [IMAP](/docs/platform-services/automation-service/app-central/integrations/imap/) <br/>- [Mail Tools](/docs/platform-services/automation-service/app-central/integrations/mail-tools/) <br/>- [POP3](/docs/platform-services/automation-service/app-central/integrations/pop3/) <br/>- [SMTP V3](/docs/platform-services/automation-service/app-central/integrations/smtp-v3/) <br/>- [Sumo Logic Cloud SIEM](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem/) <br/>- [Sumo Logic Cloud SIEM Internal](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-cloud-siem-internal/) <br/>- [Sumo Logic Log Analytics](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics/) <br/>- [Sumo Logic Log Analytics Internal](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-log-analytics-internal/) <br/>- [Sumo Logic Notifications](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications/) <br/>- [Sumo Logic Notifications by Gmail](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-gmail/)<br/>- [Sumo Logic Notifications by Microsoft](/docs/platform-services/automation-service/app-central/integrations/sumo-logic-notifications-by-microsoft)<br/>- [Triage Tools](/docs/platform-services/automation-service/app-central/integrations/triage-tools/) <br/>- [ZIP Tools](/docs/platform-services/automation-service/app-central/integrations/zip-tools/) <br/>Cloud SIEM integration: [Sumo Logic](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/34A5019C-7BEC-4BF8-A3B7-C38D567126C6.md) <br/>Collector: <br/>- [Sumo Collection](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sumo-collection-source) <br/>- [Universal Connector](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/universal-connector-source)<br/>Community app: [Cloud Security Posture Management (CSPM) for Sumo Logic](https://github.com/SumoLogic/sumologic-content/tree/master/CSPM) |
165165
| <img src={useBaseUrl('img/integrations/webhooks/superwise-logo.png')} alt="Thumbnail icon" width="50"/> | [Superwise](https://superwise.ai/) | Webhook: [Superwise](/docs/integrations/webhooks/superwise/) |
166166
| <img src={useBaseUrl('/img/send-data/symantec-logo.svg')} alt="Thumbnail icon" width="75"/> | [Symantec](https://sep.securitycloud.symantec.com/v2/landing) | App:<br/>- [Symantec Endpoint Security Service](/docs/integrations/saas-cloud/symantec-endpoint-security-service/) <br/>- [Symantec Web Security Service](/docs/integrations/saas-cloud/symantec-web-security-service/) <br/>Automation integrations: <br/>- [Javelin AD Protect](/docs/platform-services/automation-service/app-central/integrations/javelin-ad-protect/) <br/>- [Symantec DeepSight](/docs/platform-services/automation-service/app-central/integrations/symantec-deepsight/) <br/>- [Symantec EDR](/docs/platform-services/automation-service/app-central/integrations/symantec-edr/) <br/>- [Symantec Endpoint Protection](/docs/platform-services/automation-service/app-central/integrations/symantec-endpoint-protection/) <br/>- [Symantec Endpoint Protection Cloud](/docs/platform-services/automation-service/app-central/integrations/symantec-endpoint-protection-cloud/) <br/>- [Symantec Secure Web Gateway (Bluecoat)](/docs/platform-services/automation-service/app-central/integrations/symantec-secure-web-gateway-bluecoat/) <br/>- [Symantec WebPulse](/docs/platform-services/automation-service/app-central/integrations/symantec-webpulse/) <br/>Collectors: <br/>- [Symantec Endpoint Security Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-endpoint-security-source/) <br/>- [Symantec Web Security Service Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/symantec-web-security-service-source/) <br/>Cloud SIEM integration: [Symantec](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/64c7f49c-f95a-4f4a-8540-56ec5fb1d96b.md) <br/>Community app: [Sumo Logic for Symantec WSS](https://github.com/SumoLogic/sumologic-content/tree/master/Symantec/WSS) |
167-
| <img src={useBaseUrl('img/integrations/misc/sysdig-logo.png')} alt="Thumbnail icon" width="75"/> | [Sysdig](https://sysdig.com/) | Cloud SIEM integration: [Sysdig](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/c4de0854-e718-45e1-a4c8-63623755aa43.md) <br/> Collector: [Sysdig Secure](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sysdig-secure-source.md) |
167+
| <img src={useBaseUrl('img/integrations/misc/sysdig-logo.png')} alt="Thumbnail icon" width="75"/> | [Sysdig](https://sysdig.com/) | App: [Sysdig Secure](/docs/integrations/saas-cloud/sysdig-secure/) <br/>Cloud SIEM integration: [Sysdig](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/c4de0854-e718-45e1-a4c8-63623755aa43.md) <br/> Collector: [Sysdig Secure](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sysdig-secure-source.md) |
168168
| <img src={useBaseUrl('img/integrations/misc/syslog-ng-logo.png')} alt="Thumbnail icon" width="75"/> | [syslog-ng](https://www.syslog-ng.com/) | Automation integration: [Syslog-NG](/docs/platform-services/automation-service/app-central/integrations/syslog-ng/) <br/>Collector: [syslog-ng](/docs/send-data/hosted-collectors/cloud-syslog-source/syslog-ng/) |
169169

170170
## T

docs/integrations/saas-cloud/index.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -363,6 +363,12 @@ Learn about the Sumo Logic apps for SaaS and Cloud applications.
363363
<p>Gain insights into the web traffic and identify potential security threats.</p>
364364
</div>
365365
</div>
366+
<div className="box smallbox card">
367+
<div className="container">
368+
<a href="/docs/integrations/saas-cloud/sysdig-secure"><img src={useBaseUrl('img/integrations/misc/sysdig-logo.png')} alt="icon" width="120"/><h4>Sysdig Secure</h4></a>
369+
<p>Gain insights into container security to protect Kubernetes and containerized environments.</p>
370+
</div>
371+
</div>
366372
<div className="box smallbox card">
367373
<div className="container">
368374
<a href="/docs/integrations/saas-cloud/tenable"><img src={useBaseUrl('img/send-data/tenable-logo.png')} alt="icon" width="140"/><h4>Tenable</h4></a>
Lines changed: 268 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,268 @@
1+
---
2+
id: sysdig-secure
3+
title: Sysdig Secure
4+
sidebar_label: Sysdig Secure
5+
description: The Sysdig Secure app for Sumo Logic provides insights into container security and and manage runtime protection.
6+
---
7+
8+
import useBaseUrl from '@docusaurus/useBaseUrl';
9+
10+
<img src={useBaseUrl('img/integrations/misc/sysdig-logo.png')} alt="thumbnail icon" width="125"/>
11+
12+
The Sumo Logic app for Sysdig Secure integrates Sysdig Secure’s security insights with Sumo Logic's powerful analytics to help security teams monitor and protect Kubernetes and containerized environments. It provides real-time visibility into vulnerabilities, compliance, and threats by analyzing security events from various sources such as Kubernetes clusters, container registries, and runtime environments. With it's intuitive dashboards, Sysdig Secure helps security professionals understand risks, assess vulnerability impact, and monitor runtime behavior to detect threats before they affect production environments. By centralizing data and presenting it through clear visualizations, the app enables effective collaboration, proactive defense, faster remediation, and continuous compliance in dynamic, containerized environments.
13+
14+
:::info
15+
This app includes [built-in monitors](#sysdig-secure-monitors). For details on creating custom monitors, refer to [Create monitors for Sysdig Secure app](#create-monitors-for-sysdig-secure-app).
16+
:::
17+
18+
## Log types
19+
20+
This app uses Sumo Logic’s [Sysdig Secure Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sysdig-secure-source/) to collect the detected open vulnerabilities and active assets from the Sysdig Secure platform.
21+
22+
### Sample log messages
23+
24+
<details>
25+
<summary>Runtime Scan</summary>
26+
27+
```json
28+
{
29+
"mainAssetName": "mcr.microsoft.com/azure-policy/policy-kubernetes-addon-prod:1.10.1",
30+
"policyEvaluationResult": "failed",
31+
"resourceId": "sha256:73fce251be0bb71b38a642a3eed2831e5cb26e02f49023bf89fa76ce7ab2ca7d",
32+
"resultId": "18393741b66ab761884752af58d8ac32",
33+
"runningVulnTotalBySeverity": {
34+
"critical": 0,
35+
"high": 0,
36+
"low": 0,
37+
"medium": 0,
38+
"negligible": 0
39+
},
40+
"sbomId": null,
41+
"scope": {
42+
"asset.type": "workload",
43+
"kubernetes.cluster.name": "gke-alliances-test",
44+
"kubernetes.namespace.name": "kube-system",
45+
"kubernetes.pod.container.name": "konnectivity-agent-metrics-collector",
46+
"kubernetes.workload.name": "konnectivity-agent",
47+
"kubernetes.workload.type": "deployment",
48+
"workload.name": "konnectivity-agent",
49+
"workload.orchestrator": "kubernetes"
50+
},
51+
"vulnTotalBySeverity": {
52+
"critical": 0,
53+
"high": 1,
54+
"low": 1,
55+
"medium": 0,
56+
"negligible": 0
57+
}
58+
}
59+
```
60+
</details>
61+
62+
<details>
63+
<summary>Full Scan of Vulnerability</summary>
64+
65+
```json
66+
{
67+
"_resultId": "18392a48e55ef07e827e47719a5295d1",
68+
"_resourceId": "1489835514684399099",
69+
"assetType": "host",
70+
"stage": "runtime",
71+
"metadata": {
72+
"architecture": "x86_64",
73+
"hostId": "1489835514684399099",
74+
"hostName": "eksa-vsphere-conformitron-md-0-28n7h-vzqdk",
75+
"os": "bottlerocket 1.26.1"
76+
},
77+
"vulnerability": {
78+
"c360bd86-4f6d-49bf-b9ce-9fa26d2e4eac": {
79+
"cisaKev": {},
80+
"cvssScore": {
81+
"score": 5.5,
82+
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
83+
"version": "3.1"
84+
},
85+
"disclosureDate": "2024-11-19",
86+
"exploitable": false,
87+
"fixVersion": "6.1.128",
88+
"mainProvider": "bottlerocket",
89+
"name": "CVE-2024-50304",
90+
"packageRef": "ebe6d690-3753-4749-8001-b5391b9ba0a3",
91+
"providersMetadata": {
92+
"amazon": {
93+
"publishDate": "2025-02-12T22:57:00Z"
94+
},
95+
"euleros": {
96+
"publishDate": "2025-02-08T14:57:02Z"
97+
},
98+
"first.org": {
99+
"epssScore": {
100+
"score": 0.00045,
101+
"percentile": 0.13532,
102+
"timestamp": "2025-04-23T00:00:00Z"
103+
}
104+
},
105+
"nvd": {
106+
"publishDate": "2024-11-19T18:15:22.343Z",
107+
"cvssScore": {
108+
"version": "3.1",
109+
"score": 5.5,
110+
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
111+
},
112+
"severity": "medium"
113+
},
114+
"rhel": {
115+
"publishDate": "2024-11-19T00:00:00Z",
116+
"cvssScore": {
117+
"version": "3.1",
118+
"score": 5.5,
119+
"vector": "AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
120+
},
121+
"severity": "medium"
122+
},
123+
"ubuntu": {
124+
"publishDate": "2024-11-19T18:15:00Z"
125+
},
126+
"vulndb": {
127+
"publishDate": "2024-11-19T00:00:00Z"
128+
}
129+
},
130+
"riskAcceptRefs": null,
131+
"severity": "medium",
132+
"solutionDate": "2025-02-25"
133+
}
134+
}
135+
}
136+
```
137+
</details>
138+
139+
<details>
140+
<summary>Full Scan of Package</summary>
141+
142+
```json
143+
{
144+
"_resultId": "18392a48e55ef07e827e47719a5295d1",
145+
"_resourceId": "1489835514684399099",
146+
"assetType": "host",
147+
"stage": "runtime",
148+
"metadata": {
149+
"architecture": "x86_64",
150+
"hostId": "1489835514684399099",
151+
"hostName": "eksa-vsphere-conformitron-md-0-28n7h-vzqdk",
152+
"os": "bottlerocket 1.26.1"
153+
},
154+
"package": {
155+
"8edec454-c929-49b0-86e8-d72412592109": {
156+
"isRemoved": false,
157+
"isRunning": false,
158+
"name": "google.golang.org/grpc",
159+
"path": "/usr/bin/containerd-shim",
160+
"type": "golang",
161+
"version": "v1.59.0",
162+
"vulnerabilitiesRefs": null
163+
}
164+
}
165+
}
166+
```
167+
</details>
168+
169+
### Sample queries
170+
171+
```sql title="Total Running Critical Severity Vulnerabilities"
172+
_sourceCategory=Labs/SysdigSecure mainAssetName
173+
| json "mainAssetName", "resourceId", "runningVulnTotalBySeverity.critical","vulnTotalBySeverity.critical", "runningVulnTotalBySeverity.high", "vulnTotalBySeverity.high", "runningVulnTotalBySeverity.medium", "vulnTotalBySeverity.medium", "runningVulnTotalBySeverity.low", "vulnTotalBySeverity.low", "runningVulnTotalBySeverity.negligible", "vulnTotalBySeverity.negligible", "policyEvaluationResult", "$['scope']['asset.type']", "$['scope']['kubernetes.cluster.name']", "$['scope']['workload.name']", "$['scope']['kubernetes.workload.type']" as asset_name, resource_id, running_critical_vuln, total_critical_vuln, running_high_vuln, total_high_vuln, running_medium_vuln, total_medium_vuln, running_low_vuln, total_low_vuln, running_negligible_vuln, total_negligible_vuln, policy_result, asset_type, kubernete_cluster, workload_name, kubernete_workload_type nodrop
174+
175+
// global filters
176+
| where asset_type matches "{{asset_type}}"
177+
| where policy_result matches "{{policy_evaluation_result}}"
178+
| where kubernete_cluster matches "{{kubernete_cluster}}"
179+
180+
// panel specific
181+
| where !isNull(asset_name)
182+
| first(running_critical_vuln) as running_critical_vuln group by asset_name, resource_id
183+
| sum(running_critical_vuln)
184+
```
185+
186+
```sql title="Resources by Package Count"
187+
_sourceCategory=sysdig_secure_app
188+
| json "_resourceId", "assetType", "metadata.os", "metadata.architecture", "vulnerability", "package" as resource_id, asset_type, os, architecture, vuln, package nodrop
189+
| extract field=vuln "\"severity\":\s*\"(?<severity>[^\"]+)\"" nodrop
190+
| extract field=vuln "\"exploitable\":\s*(?<exploitable>true|false)" nodrop
191+
192+
// global filters
193+
| where os matches "{{os}}"
194+
| where architecture matches "{{architecture}}"
195+
| where isBlank(severity) or severity matches "{{severity}}"
196+
| where isBlank(exploitable) or exploitable matches "{{exploitable_vuln}}"
197+
198+
// panel specific
199+
| where !isNull(asset_type) and !isBlank(package)
200+
| count as package_count by resource_id
201+
| sort by package_count
202+
```
203+
204+
## Collection configuration and app installation
205+
206+
import CollectionConfiguration from '../../reuse/apps/collection-configuration.md';
207+
208+
<CollectionConfiguration/>
209+
210+
:::important
211+
Use the [Cloud-to-Cloud Integration for Sysdig Secure](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/sysdig-secure-source/) to create the source and use the same source category while installing the app. By following these steps, you can ensure that your Sysdig Secure app is properly integrated and configured to collect and analyze your Sysdig Secure data.
212+
:::
213+
214+
### Create a new collector and install the app
215+
216+
import AppCollectionOPtion1 from '../../reuse/apps/app-collection-option-1.md';
217+
218+
<AppCollectionOPtion1/>
219+
220+
### Use an existing collector and install the app
221+
222+
import AppCollectionOPtion2 from '../../reuse/apps/app-collection-option-2.md';
223+
224+
<AppCollectionOPtion2/>
225+
226+
### Use an existing source and install the app
227+
228+
import AppCollectionOPtion3 from '../../reuse/apps/app-collection-option-3.md';
229+
230+
<AppCollectionOPtion3/>
231+
232+
## Viewing the Sysdig Secure dashboards​​
233+
234+
import ViewDashboards from '../../reuse/apps/view-dashboards.md';
235+
236+
<ViewDashboards/>
237+
238+
### Runtime Scan
239+
240+
The **Sysdig Secure - Runtime Scan** dashboard provides real-time insights into the security posture of assets and Kubernetes environments during runtime. It aggregates data from Sysdig Secure’s runtime scanning API, allowing users to monitor active threats and vulnerabilities in running assets. Key features highlight vulnerabilities, track security events such as privilege escalations, and identify compliance violations. By presenting detailed information on runtime risks and potential attack vectors, the dashboard helps security professionals effectively mitigate threats and maintain secure, compliant environments.<br/><img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Sysdig+Secure/Sysdig+Secure+-+Runtime+Scan.png' alt="Runtime-Scan" />
241+
242+
### Full Scan
243+
244+
The **Sysdig Secure - Full Scan** dashboard serves as a strategic assessment tool, providing detailed information on asset packages and vulnerabilities based on results from the runtime scan API. It illustrates asset evolution over time and their distribution across operating systems and architectures. The dashboard also highlights the most frequent vulnerabilities, exploitable vulnerabilities, and detailed package data. By identifying the most at-risk assets, it supports the maintenance of a robust and secure infrastructure.<br/><img src='https://sumologic-app-data-v2.s3.us-east-1.amazonaws.com/dashboards/Sysdig+Secure/Sysdig+Secure+-+Full+Scan.png' alt="Full-Scan" />
245+
246+
## Create monitors for Sysdig Secure app
247+
248+
import CreateMonitors from '../../reuse/apps/create-monitors.md';
249+
250+
<CreateMonitors/>
251+
252+
### Sysdig Secure monitors
253+
254+
| Name | Description | Trigger Type (Critical / Warning / MissingData) | Alert Condition |
255+
|:--|:--|:--|:--|
256+
| `Sysdig Secure - Critical Vulnerabilities` | This alert is triggered when the assets with 5 or more critical severity vulnerabilities are highlighted. | Critical | Count >= 5 |
257+
258+
## Upgrading the Sysdig Secure app (Optional)
259+
260+
import AppUpdate from '../../reuse/apps/app-update.md';
261+
262+
<AppUpdate/>
263+
264+
## Uninstalling the Sysdig Secure app (Optional)
265+
266+
import AppUninstall from '../../reuse/apps/app-uninstall.md';
267+
268+
<AppUninstall/>

0 commit comments

Comments
 (0)