SmartIR
SmartIR
SmartIR provides the configuration workspace for bringing security data into SOCAutomation and controlling how that data is evaluated and acted upon. The currently documented areas cover data ingest pipelines, security alert policy, response actions and reusable global rule searches.
Select a topic below for detailed guidance.
SmartIR Overview
SmartIR separates its principal configuration areas so that inbound data, alert policy and response behaviour can be managed independently. This gives security teams a clear operational structure while allowing multiple sources, policies, actions and searches to be maintained for different requirements.
Data Ingest Pipelines
Configure the source-specific pipelines and integrations that bring security information into the platform.
Security Alert Policy
Maintain the policy settings that govern how security alerts are evaluated and handled.
Actions
Define the response and workflow actions available to SmartIR processes.
Global Rule Searches
Manage reusable search definitions used by rule-driven analysis across the platform.
Data Ingest Pipelines
Manage the integrations and pipelines that bring security data into SmartIR.
Open DocumentationSecurity Alert Policy
Review the policy configuration used to govern security alert handling.
Open DocumentationActions
Configure the response and workflow actions available to SmartIR.
Open DocumentationGlobal Rule Searches
Manage reusable search definitions that support rule-driven analysis.
Open DocumentationVideo walkthrough placeholder
Add an embedded walkthrough for this section by inserting an <iframe> or <video> element and applying the is-visible class to this container.