Demo Data
The Demo Data connector simulates incident response activities, allowing users to generate and manage alert triage records for testing and training purposes.
The Demo Data Connector is an essential tool for security teams using Swimlane Turbine to simulate and train on security incidents. It enables the creation of alert triage records within the Demo Data application, facilitating the practice of incident response processes. By integrating with Demo Data, users can customize the fields returned in each record, ensuring that they can focus on the most relevant data for their training scenarios. This connector streamlines the setup of simulated incidents, allowing teams to efficiently test and refine their security playbooks and response strategies.
Prerequisites
To effectively utilize the Demo Data connector within Swimlane Turbine, ensure you have the following prerequisites:
- HTTP Basic Authentication with the following parameters:
- URL: Endpoint for the Demo Data application.
- Username: Your Demo Data application username.
- Password: Your Demo Data application password.
- Swimlane App: The specific Swimlane application where the connector will be used.
Payload
{
"finding.uid": "str",
"sla_hours": 1,
"event.name": "str",
"user.metadata.department": "str",
"user.metadata.title": "str",
"critical-asset": "str",
"vip-user": "str",
"event.timestamp": "datetime",
"user": "str",
"authentication.metadata.modified_time": "datetime",
"meta.product.name": "str",
"src_endpoint.ip": "str",
"dst_endpoint.ip": "str",
"event.organization": "str",
"src_endpoint.hostname": "str",
"lookup-results": {
"observable": {
"type": {},
"value": {}
},
"verdict": "str",
"tool": "str"
},
"verdict": "str",
"severity": "str",
"determination": "str",
"data-points-count": "1"
}Configurations
HTTP Basic Authentication
Authenticates using username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
username | Username | string | Required |
password | Password | string | Required |
swapp | Swimlane App to insert the records | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Create Alert Triage Records
Generates new alert triage records within the Demo Data application to streamline incident response processes.
Endpoint
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
records_to_create | number | Optional | Parameter for Create Alert Triage Records |
required_fields | array | Optional | Fields to be returned. Defaults to all |
Input Example
{"records_to_create":5,"required_fields":"finding.uid"}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |