The purpose of the Cyware Orchestrate app is to enable integration of the Cyware Orchestrate (CO) platform with Splunk Enterprise or Splunk Cloud. This app can push triggered alert event data and/or notable Events from Splunk to Cyware Orchestrate. Once the app is successfully installed and configured to a Splunk search head, analysts can utilize it to perform the configured forwarding actions. On receiving the event data, Cyware Orchestrate ingests the Source/Triggered Event data and will execute any applicable Playbooks available for the given event/label type. The actions configured in the Playbook will then be performed with the Splunk Event data as an input to the workflow.
(0)
Categories
Created By
Type
Downloads
Licensing
Splunk Answers
Resources