Skip to content

Commit

Permalink
update links
Browse files Browse the repository at this point in the history
  • Loading branch information
Jake Lee committed Oct 1, 2024
1 parent e1966ae commit 5e91849
Show file tree
Hide file tree
Showing 33 changed files with 20 additions and 20 deletions.
6 changes: 3 additions & 3 deletions Amazon_Web_Services/AWS_Health/README.md
Original file line number Diff line number Diff line change
@@ -1,18 +1,18 @@
# Sumo Logic for AWS Health Events
Sumo Logic Community Content built for AWS Health Events that are not yet published to the [App Catalog](https://help.sumologic.com/docs/integrations/).

This content provides a way to forward AWS Health Events to a [Sumo Logic HTTP Source](https://help-opensource.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/) using Amazon EventBridge. The integration from EventBridge leverages the [Sumo Logic Partner Destination](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-api-destination-partners.html#:~:text=HEC%20token%20ID.-,Sumo%20Logic,-API%20destination%20invocation). For more information on AWS Health Events forwarding, please see [Monitoring AWS Health events with Amazon EventBridge](https://docs.aws.amazon.com/health/latest/ug/cloudwatch-events-health.html).
This content provides a way to forward AWS Health Events to a [Sumo Logic HTTP Source](https://help.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/) using Amazon EventBridge. The integration from EventBridge leverages the [Sumo Logic Partner Destination](https://docs.aws.amazon.com/eventbridge/latest/userguide/eb-api-destination-partners.html#:~:text=HEC%20token%20ID.-,Sumo%20Logic,-API%20destination%20invocation). For more information on AWS Health Events forwarding, please see [Monitoring AWS Health events with Amazon EventBridge](https://docs.aws.amazon.com/health/latest/ug/cloudwatch-events-health.html).

### To use the content:
**For A Single Account:**
- Copy/download the two Cloudformation templates (1-aws-health-events-to-sumo-logic-iam-role.yaml and 2-aws-health-events-to-sumo-logic-event-rule.yaml).
- Run the IAM Role template in the AWS Account you want to collect from first, and copy the ARN output for the IAM Role. **Only create this Role once per AWS Account.**
- Run the Event Rule template and provide the [Sumo Logic HTTP Source URL](https://help-opensource.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/) and the output IAM Role ARN from the first template. Run this template in any Region you want to collect health events from.
- Run the Event Rule template and provide the [Sumo Logic HTTP Source URL](https://help.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/) and the output IAM Role ARN from the first template. Run this template in any Region you want to collect health events from.

**For Multi Account/Region:**
- Copy/download the two Cloudformation templates (1-aws-health-events-to-sumo-logic-iam-role.yaml and 2-aws-health-events-to-sumo-logic-event-rule.yaml).
- Run the IAM Role template in each AWS Account you want to collect from first, and copy the ARN output for the IAM Role. **Only create this Role once per AWS Account.**
- Use Cloudformation StackSets to run the Event Rule template in multiple accounts/regions, and provide the [Sumo Logic HTTP Source URL](https://help-opensource.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/) and the output IAM Role ARN from the first template.
- Use Cloudformation StackSets to run the Event Rule template in multiple accounts/regions, and provide the [Sumo Logic HTTP Source URL](https://help.sumologic.com/docs/send-data/hosted-collectors/http-source/logs-metrics/) and the output IAM Role ARN from the first template.

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
2 changes: 1 addition & 1 deletion CloudSOAR/Integrations/Armorblox/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ Sumo Logic Custom CloudSOAR Integration for Armorblox, provided by the community
- Download the Integration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings (⚙)(top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
2 changes: 1 addition & 1 deletion CloudSOAR/Integrations/Automation-Tools/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ This integration is in active development. Actions, or the parameters defined th
- Download the Integration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings (⚙)(top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

## Action Descriptions
### Data Transform
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ A supplemental action for Sumo Logic CloudSOAR's AzureAD Integration, provided b
- Download the Integration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings cogwheel (top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -11,7 +11,7 @@ The actions included in this integration have been published to App Central unde
- Download the Integration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings (⚙)(top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

## Action Descriptions
NOTE: The actions included in this integration have been published to App Central under [Incident Tools](https://help.sumologic.com/docs/platform-services/automation-service/app-central/integrations/incident-tools/). They remain here for reference purposes
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ Sumo Logic Custom CloudSOAR Integration for Proofpoint End User Management (Proo
- Download the Integatration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings cogwheel (top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
2 changes: 1 addition & 1 deletion CloudSOAR/Integrations/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ Sumo Logic Custom CloudSOAR Integrations provided by the community.
- Download the Integatration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings cogwheel (top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
4 changes: 2 additions & 2 deletions CloudSOAR/Integrations/Screenshot Machine/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ Sumo Logic Custom CloudSOAR Integration for Screenshot Machine, provided by the
1. Integration YAML File: Integration configurations and test code.
2. Action YAML File(s):
- Screenshot Webpage (Enrichment) - This updated action has been enhanced to provide the following:
- Render PNG image in an Action Result - Uses output type [image_base64_png](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#added-more-output-type-for-action).
- Render PNG image in an Action Result - Uses output type [image_base64_png](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#added-more-output-type-for-action).
- Provides the encoded base64 string as part of the action result, which can also be used in a playbook when using an action with an 'upload' field type, such as Automation Tools' [Render PNG Image](<../Automation-Tools/actions/Render PNG Image.yaml>) action.
- Image attached as an Incident Attachment

Expand All @@ -18,7 +18,7 @@ Sumo Logic Custom CloudSOAR Integration for Screenshot Machine, provided by the
- Download the Integration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings cogwheel (top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
2 changes: 1 addition & 1 deletion CloudSOAR/Integrations/ServiceNow/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ Sumo Logic Custom CloudSOAR Integration for ServiceNow, provided by the communit
- Download the Integatration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings cogwheel (top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,11 @@ This integration is in active development. Actions, or the parameters defined th
- Download the Integration and Action YAML files to your local device.
- Create a new Cloud SOAR integration by logging into CloudSOAR > going to Settings (⚙)(top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

## Action Descriptions
### Add Indicator to Threat Intel Source
- Accepts a single IP, or comma-separated list of IPs and searches for IOCs using Sumo Logic's [threatip()](https://help-opensource.sumologic.com/docs/search/search-query-language/search-operators/threatip/) operator.
- Accepts a single IP, or comma-separated list of IPs and searches for IOCs using Sumo Logic's [threatip()](https://help.sumologic.com/docs/search/search-query-language/search-operators/threatip/) operator.
### Create Threat Intel Source
- Creates a [Threat Intel Source](https://help.sumologic.com/docs/cse/rules/about-cse-rules/#threat-intelligence) in Cloud SIEM.
### Get Threat Intel Indicator
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,11 +12,11 @@ This integration is in active development. Actions, or the parameters defined th
- Download the Integration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings (⚙)(top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

## Action Descriptions
### Threat IP Search
- Accepts a single IP, or comma-separated list of IPs and searches for IOCs using Sumo Logic's [threatip()](https://help-opensource.sumologic.com/docs/search/search-query-language/search-operators/threatip/ operator.
- Accepts a single IP, or comma-separated list of IPs and searches for IOCs using Sumo Logic's [threatip()](https://help.sumologic.com/docs/search/search-query-language/search-operators/threatip/ operator.
- **IP Addresses** - IP Address(es) (single or comma-separated) to search for using "threatip()" search operator (e.g. "0.0.0.0, 0.0.0.0" or manually input each IP and hit 'enter').
- Tip: The Automation Tools > "Render Textarea Field" action would be useful here to "build" a list of IPs composed of a series of JSON placeholders.
- **Source Category** - If no source category is provided, a wildcard ("*") will be used.
Expand Down
2 changes: 1 addition & 1 deletion CloudSOAR/Playbooks/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ Playbooks in Cloud SOAR, when exported, are delivered as a zip archive. However,
### Using an Imported Playbook
Note: Once a playbook is imported, it is not functional out-of-the-box. You must edit the playbook to provide **Action Type** and **Action** parameters, though the inputs to these action should be pre-populated once selected.

For more information on working with playbooks in Cloud SOAR, please see [Cloud SOAR Playbooks](https://help-opensource.sumologic.com/docs/cloud-soar/automation/#playbook).
For more information on working with playbooks in Cloud SOAR, please see [Cloud SOAR Playbooks](https://help.sumologic.com/docs/cloud-soar/automation/#playbook).


### To upload your own content:
Expand Down
2 changes: 1 addition & 1 deletion CloudSOAR/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ See [Integrations](https://github.com/SumoLogic/sumologic-content/tree/master/Cl
- Download the Integatration and Action YAML files to your local device.
- Create a new CloudSOAR integration by logging into CloudSOAR > going to Settings cogwheel (top right) > Automation > Integrations > Plus(+) icon > and selecting the Integration YAML file.
- Add any Actions you downloaded to that Integration by selecting the Upload icon (hover over the newly added integration), and uploading the Action YAML file(s).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help-opensource.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).
- For more information on uploading custom Integrations/Actions and how to test them, please see [Working with integrations](https://help.sumologic.com/docs/cloud-soar/cloud-soar-integration-framework/#working-with-integrations).

### To upload your own content:
Please see [Sumo Logic Community Ecosystem Apps FAQs](https://help.sumologic.com/docs/integrations/community-ecosystem-apps/#faq).
Expand Down
Loading

0 comments on commit 5e91849

Please sign in to comment.