Cisco Secure Endpoint Alert

This rule is part of a beta feature. To learn more, contact Support.

Set up the cisco-secure-endpoint integration.

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Goal

Detect alerts generated by Cisco Secure Endpoint.

Strategy

This rule monitors alerts logs generated by Cisco Secure Endpoint.

Triage and response

  1. Analyse the {{@event.severity}} severity event on hostname {{@event.computer.hostname}}.
  2. Investigate specific alert details and context to determine the threat impact.
  3. Take necessary and appropriate actions based on company procedures.
PREVIEWING: may/embedded-workflows