Cofense Triage

Supported OS Linux Windows Mac OS

marketplace
Integration version1.0.0

Overview

Cofense Triage is a phishing threat management platform that automates the detection, analysis, and response to phishing emails by leveraging user-reported data. This integration enhances security workflows by providing real-time visibility into phishing incidents identified by Cofense Triage directly within Datadog for faster, coordinated responses.

This integration collects the following:

Metrics

cds.cofense_triage.health.cpu_usage_percent
(gauge)
CPU usage percentage of Cofense Triage server
Shown as percent
cds.cofense_triage.health.memory_in_kilobytes.active_memory
(gauge)
Active memory of Cofense Triage server
Shown as kilobyte
cds.cofense_triage.health.memory_in_kilobytes.free_memory
(gauge)
Free memory of Cofense Triage server
Shown as kilobyte
cds.cofense_triage.health.memory_in_kilobytes.inactive_memory
(gauge)
Inactive memory of Cofense Triage server
Shown as kilobyte
cds.cofense_triage.health.memory_in_kilobytes.total_memory
(gauge)
Total memory of Cofense Triage server
Shown as kilobyte
cds.cofense_triage.health.memory_in_kilobytes.used_memory
(gauge)
Used memory of Cofense Triage server
Shown as kilobyte
cds.cofense_triage.partition_used_percent
(gauge)
partition_used_percentage of Cofense Triage server
Shown as percent
cds.cofense_triage.status
(gauge)
System status of Cofense Triage server
cds.cofense_triage.statistics.new_reports
(gauge)
New reports on Cofense Triage
cds.cofense_triage.statistics.processed_reports
(gauge)
Processed reports on Cofense Triage
cds.cofense_triage.statistics.unprocessed_reports
(gauge)
Unprocessed reports on Cofense Triage
cds.cofense_triage.statistics.unparsed_emails
(gauge)
Unparsed emails on Cofense Triage
cds.cofense_triage.top_categories.count
(gauge)
Counts of top categories
cds.cofense_triage.top_processing_api_applications.count
(gauge)
Counts of top api applications
cds.cofense_triage.top_processing_operators.count
(gauge)
Counts of top processing operators
cds.cofense_triage.top_reporters.count
(gauge)
Counts of top reporters
cds.cofense_triage.top_rules.count
(gauge)
Counts of top rules

Logs

  • Reports
  • Threat Indicators
  • Urls
  • Domains
  • Attachments
  • Attachment Payloads
  • Clusters
  • Headers
  • Hostnames
  • Playbooks
  • Rules
  • Categories
  • Comments
  • Identity Providers
  • Integrations
  • Dynamic Reporting Outputs

Events

  • Authentication
  • Configuration Validation

Dashboards

This integration includes the following out-of-the-box dashboards:

  1. Status: Provides system status information, including CPU usage and partition usage of the Cofense Triage server.
  2. Executive Summary: Offers a summary of the Cofense Triage reporting data.
  3. Reporting Output: Displays a detailed reporting output, consisting of reports and their corresponding data.
  4. Overview: Includes handpicked details taken from the aforementioned dashboards.

Support

For support or feature requests, contact Crest Data through the following channels:

Troubleshooting

Need help? Contact Datadog support.


This application is made available through the Marketplace and is supported by a Datadog Technology Partner. Click Here to purchase this application.

PREVIEWING: guacbot/translation-pipeline