Skip to content

SIEM/SOAR export (syslog/CEF) for alerts #80

@WhiteMuush

Description

@WhiteMuush

Why

Enterprise buyers require alerts to flow into their SOC tooling. Platforms are expected to integrate with SIEM/SOAR; without it DataShield cannot fit an existing security operations pipeline.

Scope

  • Structured export of alerts and findings as syslog (RFC 5424) and CEF for Splunk / Microsoft Sentinel ingestion.
  • Push (syslog endpoint) and pull (authenticated JSON feed) modes.
  • Stable field mapping documented for SIEM parsers.

Hooks

  • New src/lib/integrations/ (CEF/syslog formatters), ApiCredential for endpoint auth, scheduler for batched push.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions