SmartIR

SmartIR

SmartIR provides the configuration workspace for bringing security data into SOCAutomation and controlling how that data is evaluated and acted upon. The currently documented areas cover data ingest pipelines, security alert policy, response actions and reusable global rule searches.

Select a topic below for detailed guidance.

SmartIR interface showing the Data Ingest Pipelines list and the main configuration tabs
SmartIR configuration workspace showing the Data Ingest Pipelines area and its current pipeline list.

SmartIR Overview

SmartIR separates its principal configuration areas so that inbound data, alert policy and response behaviour can be managed independently. This gives security teams a clear operational structure while allowing multiple sources, policies, actions and searches to be maintained for different requirements.

Data Ingest Pipelines

Configure the source-specific pipelines and integrations that bring security information into the platform.

Security Alert Policy

Maintain the policy settings that govern how security alerts are evaluated and handled.

Actions

Define the response and workflow actions available to SmartIR processes.

Global Rule Searches

Manage reusable search definitions used by rule-driven analysis across the platform.

Data Ingest Pipelines

Manage the integrations and pipelines that bring security data into SmartIR.

Open Documentation

Security Alert Policy

Review the policy configuration used to govern security alert handling.

Open Documentation

Actions

Configure the response and workflow actions available to SmartIR.

Open Documentation

Global Rule Searches

Manage reusable search definitions that support rule-driven analysis.

Open Documentation

Video walkthrough placeholder

Add an embedded walkthrough for this section by inserting an <iframe> or <video> element and applying the is-visible class to this container.

Example: <div class="video-placeholder is-visible">...</div>