NDR solutions offers alert notification capabilities to centralize threat monitoring and log analysis for security teams. It integrates seamlessly with Security Information and Event Management (SIEM) solutions such as Helix, Splunk, and Chronicle, and generic Syslog servers. Analysts can benefit from this data ingestion by centrally monitoring all threats and logs from assets across their network.
NDR supports sending alerts using either HTTP or RSYSLOG methods. It offers a wide array of formats to accommodate diverse SIEM requirements, including Common Event Format (CEF), Comma Separated Values (CSV), JavaScript Object Notation (JSON), Log Event Extended Format (LEEF), syslog formatted messages (SYSLOG), and Extensible Markup Language (XML). This allows users have granular control over alert notifications, enabling them to specify the alert severity level and the frequency at which notifications are sent.
You can integrate the SIEM solutions with your NDR appliance through CLI and Web UI.