This guide helps you get started with the Automation module (previously called Continuous Content Management, or CCM) and make the most of its capabilities. The module can be found under the Automation category in Threat Detection Marketplace on the SOC Prime Platform.
The Automation module allows keeping your SIEM up-to-date with the latest compatible SOC content, manage the content, make changes to it on the fly, and deploy these changes.
You can automatically deploy content both from the Platform and custom repositories.
Access to the Automation functionality depends on your Threat Detection Marketplace subscription plan.
The module includes the following functionality:
Name | Description |
Comprehensive view of all content in the selected Data Plane. Manage content in your organization's SIEM, drill down to specific detections from the SOC Prime Platform, edit content and deploy changes. | |
Logs of all automated and manual content management actions across your organization. | |
Automated content deployment. Set up Jobs to perform content management actions on the lists that are available to you. |
In addition, the following capabilities of the SOC Prime Platform are relevant to the module:
Name | Description |
Collections of content items. Arrange content from Threat Detection Marketplace into lists to perform bulk automated deployments and make updates through Jobs. | |
Automated content deployment customization for your organization's SIEM. Create Presets and link them to Jobs. | |
Additional conditions to be added to the detection logic before deployment. Configure Filters and link them to Presets. | |
Integration with your SIEM, EDR, XDR, or Data Lake instances to enable deploying rules |
Start with setting up a Data Plane for your platform. Currently, Automation supports integration with the following platforms:
Microsoft Sentinel
Elastic Stack
Falcon LogScale
Sumo Logic
Google SecOps
Splunk (via integration app)
Note:
SOC Prime is not liable for any SIEM issues related to the use of the Automation module.
By using the Automation module, you are solely liable for any failures, disruptions, damages, or data loss in your SIEM when you update content and re-deploy the changes to your Data Plane. |
After setting up a Data Plane integration, you can run the Inventory to keep it in sync with your organization's SIEM pulling all content available in it to the Automation module. This way, you will be able to manage all content in one place.
Now you are ready to create Content Lists, set up Jobs to deploy them, and customize Jobs with Presets and Filters.
Note:
|
