Skip to content

Commit ca665e1

Browse files
authored
Merge branch 'main' into update-search-job-doc
2 parents 00a7c99 + 9a1dedb commit ca665e1

File tree

54 files changed

+422
-643
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

54 files changed

+422
-643
lines changed

blog-service/2024-05-13-apps.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,15 +16,15 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
1616
We're excited to announce increased visibility into your AWS Cloud environment with the following new features:
1717
* **Out-of-the-box security policy checks**. Sumo Logic Cloud Infrastructure Security is now configured by default to use the out-of-the box policy checks. You can now choose to leverage the out-of-the-box policy checks instead of, or in conjunction with, the policy checks provided by AWS Security Hub.
1818
* **Additional investigation capabilities**. The update includes the addition of three new dashboards:
19-
* [**Infrastructure Overview**](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/#infrastructure-overview). Get deep visibility into your cloud infrastructure to understand how many cloud resources are running and their configurations.
20-
* [**Security Control Failures Overview**](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/#security-control-failures-overview). See misconfigurations in your environment that may leave you vulnerable to attackers.
21-
* [**Security Control Failures Investigation**](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/#security-control-failures-investigation). Navigate and prioritize the most important misconfigurations in your environment.
19+
* **Infrastructure Overview**. Get deep visibility into your cloud infrastructure to understand how many cloud resources are running and their configurations.
20+
* **Security Control Failures Overview**. See misconfigurations in your environment that may leave you vulnerable to attackers.
21+
* **Security Control Failures Investigation**. Navigate and prioritize the most important misconfigurations in your environment.
2222
* **AI-powered remediation plans**. You can now use automated remediation playbooks built specifically for Cloud Infrastructure Security for AWS.
2323

2424
This functionality is in preview. To participate, reach out to your Sumo Logic account executive.
2525

2626
[Learn more](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).
2727

2828
:::note
29-
As part of the preview, you can use CloudQuery logs with Cloud Infrastructure Security for AWS. To use the logs, configure the CloudQuery source when you [deploy the solution](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/#step-3-deploy-aws).
29+
As part of the preview, you can use CloudQuery logs with Cloud Infrastructure Security for AWS. To use the logs, configure the CloudQuery source when you deploy the solution.
3030
:::

blog-service/2024-10-21-apps-2.md

Lines changed: 16 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,16 @@
1+
---
2+
title: Atlassian (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- atlassian
6+
- apps
7+
hide_table_of_contents: true
8+
---
9+
10+
import useBaseUrl from '@docusaurus/useBaseUrl';
11+
12+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
13+
14+
We're excited to introduce the new Atlassian app for Sumo Logic. This app leverages the Sumo Logic Cloud-to-Cloud Atlassian source to collect events logs through the Events API, helping you to to monitor critical events such as user activities, policy changes, group and API token creations, and product access.
15+
16+
Explore our technical documentation [here](/docs/integrations/saas-cloud/atlassian/) to learn how to set up and use the Atlassian app for Sumo Logic.

blog-service/2024-10-21-apps.md

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
---
2+
title: Enhancements to Cloud Infrastructure Security for AWS (Apps)
3+
image: https://help.sumologic.com/img/sumo-square.png
4+
keywords:
5+
- apps
6+
- app catalog
7+
- aws
8+
- cloud infrastructure security
9+
hide_table_of_contents: true
10+
---
11+
12+
import useBaseUrl from '@docusaurus/useBaseUrl';
13+
14+
<a href="https://help.sumologic.com/release-notes-service/rss.xml"><img src={useBaseUrl('img/release-notes/rss-orange2.png')} alt="icon" width="50"/></a>
15+
16+
We're happy to announce enhancements to Cloud Infrastructure for AWS. These capabilities were [previously only available in a preview form](/release-notes-service/2024/05/13/apps/). They are now available for general use.
17+
18+
You can now more easily configure sources on a simplified screen, allowing you to use existing sources or create new sources.
19+
20+
<img src={useBaseUrl('img/integrations/amazon-aws/cis-for-aws-install-0.png')} alt="Configure Sources screen" style={{border: '1px solid gray'}} width="700"/>
21+
22+
[Learn more](/docs/security/cloud-infrastructure-security/cloud-infrastructure-security-for-aws/).

cid-redirects.json

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1578,6 +1578,7 @@
15781578
"/cid/10204": "/docs/integrations/saas-cloud/cato-networks",
15791579
"/cid/10198": "/docs/integrations/saas-cloud/microsoft-graph-azure-ad-reporting",
15801580
"/cid/10193": "/docs/integrations/saas-cloud/asana",
1581+
"/cid/10181": "/docs/integrations/saas-cloud/atlassian",
15811582
"/cid/10197": "/docs/integrations/saas-cloud/symantec-web-security-service",
15821583
"/cid/10112": "/docs/integrations/app-development/jfrog-xray",
15831584
"/cid/10113": "/docs/observability/root-cause-explorer",
@@ -2645,9 +2646,9 @@
26452646
"/cid/19901": "/docs/metrics/metrics-operators/topk",
26462647
"/cid/19902": "/docs/metrics/metrics-operators/where",
26472648
"/cid/15631": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/citrix-cloud-source",
2648-
"/cid/15634": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cloudquery-gcp-source",
2649-
"/cid/15632": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cloudquery-azure-plugin-source",
2650-
"/cid/15633": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/cloudquery-source",
2649+
"/cid/15634": "/docs/c2c/info/",
2650+
"/cid/15632": "/docs/c2c/info/",
2651+
"/cid/15633": "/docs/c2c/info/",
26512652
"/cid/14323": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/docusign-source",
26522653
"/cid/14324": "/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/zendesk-source",
26532654
"/cid/14326": "/docs/integrations/global-intelligence/kubernetes-devops",

docs/alerts/webhook-connections/cloud-soar.md

Lines changed: 38 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -16,14 +16,44 @@ import useBaseUrl from '@docusaurus/useBaseUrl';
1616
* You'll need the **Manage connections** [role capability](/docs/manage/users-roles/roles/role-capabilities) to create webhook connections.
1717
:::
1818

19-
To create a webhook connection from Sumo Logic to Cloud SOAR:
19+
You can configure a webhook connection to allow you to send an alert from a scheduled search to Sumo Logic Cloud SOAR using an incident template.
2020

2121
1. [**Classic UI**](/docs/get-started/sumo-logic-ui-classic). In the main Sumo Logic menu, select **Manage Data > Monitoring > Connections**. <br/>[**New UI**](/docs/get-started/sumo-logic-ui). In the top menu select **Configuration**, and then under **Monitoring** select **Connections**. You can also click the **Go To...** menu at the top of the screen and select **Connections**.
22-
1. Click **+ Add** and choose **Cloud SOAR** as the connection type.<br/> <img src={useBaseUrl('img/connection-and-integration/SOAR-webhook-icon.png')} alt="SOAR webhook icon.png" width="200"/>
23-
1. Enter a **Name** and give an optional **Description** to the connection.
24-
1. The **URL** and **Authorization Header** are automatically defined by Sumo Logic. You should not edit these.
25-
1. The **Templates** dropdown shows a list of all incident templates, by name, configured in your Cloud SOAR environment.
26-
1. The default **Payload** synchronizes with the selected template and the associated `template_id` field is automatically defined in the default payload. A `template_id` is required in the payload in order to configure the connection. For details on variables you can use as parameters within your JSON object, see [Webhook Payload Variables](set-up-webhook-connections.md).
27-
1. Click **Save**.
22+
1. Click **+** and choose **Cloud SOAR** as the connection type. The **Create Cloud SOAR Connection** dialog is displayed.<br/><img src={useBaseUrl('img/cloud-soar/CSOAR-connection1.png')} alt="New connection" style={{border: '1px solid gray'}} width="600"/>
23+
1. Enter a **Name** and give an optional **Description** to the connection.
24+
1. The **URL** field shows your [Sumo Logic API endpoint](/docs/api/getting-started#sumo-logic-endpoints-by-deployment-and-firewall-security) followed by `/csoar/v3/incidents/`. For example, `https://api.us2.sumologic.com/api/csoar/v3/incidents/`
25+
1. In **Authorization Header**, enter your basic authentication access information for the header. For example, `Basic <base64 encode <accessId>:<accessKey>>`. For more information, see [Basic Access (Base64 encoded)](/docs/api/getting-started#basic-access-base64-encoded).
26+
1. Click **Save**. After save, the **Templates** dropdown shows a list of all incident templates by name configured in your Cloud SOAR environment.
27+
1. Select a **Template**.
28+
1. The default payload synchronizes with the selected template, and the **Alert Payload** field shows the associated `template_id` field automatically defined in the default payload. A `template_id` is required in the payload in order to configure the connection:
29+
30+
```
31+
{
32+
"template_id": <Template ID>,
33+
"fields": {
34+
"incidentid": "Incident Id"
35+
}
36+
}
37+
```
2838
29-
For more detailed instructions, see [Configure a webhook for Cloud SOAR](/docs/cloud-soar/automation/#configure-a-webhook-for-cloud-soar).
39+
You can add additional variables. For example:
40+
41+
```
42+
{
43+
"fields": {
44+
"description": "string",
45+
"additional_info": "string",
46+
"starttime": "ISO-8601 datetime string",
47+
"incident_kind": <ID incident kind>,
48+
"incident_category": <ID incident category>,
49+
"status": <ID incident status>,
50+
"restriction": <ID incident restriction>
51+
}
52+
}
53+
```
54+
:::note
55+
* For details on variables you can use as parameters within your JSON object, see [Configure Webhook Payload Variables](/docs/alerts/webhook-connections/set-up-webhook-connections/#configure-webhook-payload-variables).
56+
* For information on additional fields, please refer to the [Cloud SOAR APIs](/docs/api/cloud-soar/) documentation.
57+
* The preceding example shows an `ISO-8601 datetime string`. For information about how to configure it, see [parser documentation](https://dateutil.readthedocs.io/en/stable/parser.html#dateutil.parser.isoparse).
58+
:::
59+
1. Click **Save**.

docs/integrations/product-list/product-list-a-l.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -77,7 +77,7 @@ For descriptions of the different types of integrations Sumo Logic offers, see [
7777
| <img src={useBaseUrl('img/integrations/misc/aria-logo.png')} alt="Thumbnail icon" width="50"/> | [Aria](https://www.ariacybersecurity.com/cybersecurity-products/aria-packet-intelligence/) | Partner integration: [Aria](https://www.ariacybersecurity.com/aria-packet-intelligence-app/) |
7878
| <img src={useBaseUrl('img/send-data/armis-icon.png')} alt="Thumbnail icon" width="75"/> | [Armis](https://www.armis.com/) | App: [Armis](/docs/integrations/saas-cloud/armis/) <br/>Collector: [Armis API Integration Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/armis-api-source/) |
7979
| <img src={useBaseUrl('img/send-data/asana-icon.png')} alt="Thumbnail icon" width="50"/> | [Asana](https://asana.com/) | App: [Asana](/docs/integrations/saas-cloud/asana/) <br/>Collector: [Asana Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/asana-source/) |
80-
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/atlassian-confluence.png')} alt="Thumbnail icon" width="75"/> | [Atlassian](https://www.atlassian.com) | Apps: <br/>- [Jira](/docs/integrations/app-development/jira/) <br/>- [Jira Cloud](/docs/integrations/app-development/jira-cloud/) <br/>- [Jira - OpenTelemetry](/docs/integrations/app-development/opentelemetry/jira-opentelemetry/) <br/>Automation integrations: <br/>- [Atlassian Confluence](/docs/platform-services/automation-service/app-central/integrations/atlassian-confluence/) <br/>- [Atlassian Jira](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira/) <br/>- [Atlassian Jira V2](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2/) <br/>Collector: [Atlassian Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/atlassian-source/)<br/>Cloud SIEM integration: [Atlassian](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/4d40dc7a-b95e-476c-9fb0-7163ea7fd335.md) <br/>Webhooks: <br/>- [Webhook Connection for Jira Cloud](/docs/alerts/webhook-connections/jira-cloud/) <br/>- [Webhook Connection for Jira Server](/docs/alerts/webhook-connections/jira-server/) <br/>- [Webhook Connection for Jira Service Desk](/docs/alerts/webhook-connections/jira-service-desk/) |
80+
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/atlassian-confluence.png')} alt="Thumbnail icon" width="75"/> | [Atlassian](https://www.atlassian.com) | Apps: <br/>- [Atlassian](/docs/integrations/saas-cloud/atlassian/) <br/>- [Jira](/docs/integrations/app-development/jira/) <br/>- [Jira Cloud](/docs/integrations/app-development/jira-cloud/) <br/>- [Jira - OpenTelemetry](/docs/integrations/app-development/opentelemetry/jira-opentelemetry/) <br/>Automation integrations: <br/>- [Atlassian Confluence](/docs/platform-services/automation-service/app-central/integrations/atlassian-confluence/) <br/>- [Atlassian Jira](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira/) <br/>- [Atlassian Jira V2](/docs/platform-services/automation-service/app-central/integrations/atlassian-jira-v2/) <br/>Collector: [Atlassian Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/atlassian-source/)<br/>Cloud SIEM integration: [Atlassian](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/4d40dc7a-b95e-476c-9fb0-7163ea7fd335.md) <br/>Webhooks: <br/>- [Webhook Connection for Jira Cloud](/docs/alerts/webhook-connections/jira-cloud/) <br/>- [Webhook Connection for Jira Server](/docs/alerts/webhook-connections/jira-server/) <br/>- [Webhook Connection for Jira Service Desk](/docs/alerts/webhook-connections/jira-service-desk/) |
8181
| <img src={useBaseUrl('img/integrations/misc/automation-anywhere-logo.png')} alt="Thumbnail icon" width="50"/> | [Automation Anywhere](https://www.automationanywhere.com/) | Partner integration: [Automation Anywhere](https://docs.automationanywhere.com/bundle/enterprise-v2019/page/enterprise-cloud/topics/control-room/administration/settings/setting-up-sumo-logic.html) |
8282
| <img src={useBaseUrl('img/platform-services/automation-service/app-central/logos/automox.png')} alt="Thumbnail icon" width="100"/> | [Automox](https://www.automox.com/) | Automation integration: [Automox](/docs/platform-services/automation-service/app-central/integrations/automox/) <br/>Collector: [Automox Source](/docs/send-data/hosted-collectors/cloud-to-cloud-integration-framework/automox-source) |
8383
| <img src={useBaseUrl('img/integrations/saml/auth0.png')} alt="Thumbnail icon" width="50"/> | [Auth0](https://auth0.com/) | App: [Auth0](/docs/integrations/saml/auth0/) <br/>Cloud SIEM integration: [Auth0](https://github.com/SumoLogic/cloud-siem-content-catalog/blob/master/vendors/f002a19c-876e-4a33-8be0-ed3b922d19bc.md) <br/>Collector: [Auth0 - Cloud SIEM](/docs/cse/ingestion/ingestion-sources-for-cloud-siem/auth0/) <br/>Partner integration: [Auth0](https://auth0.com/docs/customize/log-streams/sumo-logic-dashboard) |

0 commit comments

Comments
 (0)