Stellar SIEM
Stellar SIEM is a robust platform that provides advanced threat detection and security analytics to protect enterprise networks.
Stellar SIEM is a comprehensive security information and event management platform designed to enhance threat detection and response capabilities. By integrating with Swimlane Turbine, users can automate security incident management tasks such as case creation, alert retrieval, and Elasticsearch queries. This integration empowers security teams to streamline operations, improve incident response times, and gain deeper insights into security events, all without the need for extensive coding.
Limitations
The alerts endpoint returns at most 50 results per request; use skip and limit for pagination (e.g. second page: skip=10&limit=10). The Execute Elasticsearch Job action may require custom code depending on query structure.
Supported Versions
This Stellar SIEM connector uses the Stellar Cyber public API (v1). Refer to Stellar Cyber API documentation for version-specific details.
Additional Docs
Configuration
Prerequisites
Before you can use the Stellar SIEM connector for Turbine, you'll need access to the Stellar SIEM API. This requires the following:
- HTTP Bearer authentication using the following parameters:
- URL: The endpoint URL for accessing Stellar SIEM API.
- Token: A valid bearer token for authenticating API requests.
- HTTP Basic authentication using the following parameters:
- URL: The endpoint URL for accessing Stellar SIEM API.
- Username: Your Stellar SIEM account username.
- Password: Your Stellar SIEM account password.
Authentication Methods
HTTP Basic Authentication
- URL: The base URL of your Stellar Cyber server (e.g. https://myserver.stellarcyber.cloud).
- Username: Stellar Cyber user (typically the account email).
- Password: Password for the user (or API key when the user authenticates with one).
Stellar Cyber only accepts HTTP Basic credentials on /connect/api/v1/access_token; every other endpoint requires a JWT bearer token. The connector handles this transparently in connector/src/runner_override.py, which overrides the framework's http_basic auth handler. On every action invocation it:
- POSTs to /connect/api/v1/access_token with Authorization: Basic <Base64(username:password)> and Content-Type: application/x-www-form-urlencoded to mint a fresh JWT.
- Attaches Authorization: Bearer <jwt> to the runner's HTTP session.
From there the framework's default action runner issues the actual API call with the bearer token already on the session, so every action - including Execute Elasticsearch Job - works against the customer's http_basic asset without per-action customization. JWTs expire after 10 minutes; a new one is minted on every action invocation.
HTTP Bearer Authentication
- URL: The base URL of your Stellar Cyber server (e.g. https://myserver.stellarcyber.cloud).
- Token: JWT obtained from POST /connect/api/v1/access_token using your email and API key (Basic auth). Use a dedicated API user and refresh the token as needed; tokens expire in 10 minutes.
Capabilities
This Stellar SIEM connector provides the following capabilities:
- List Cases
- Get Case Scores
- Retrieve Paginated Alerts
- Execute Elasticsearch Job
- List Connectors
- List Tenants
- Create Connector
- List Users
- Add Comment to a Case
- Update Case
List Cases
Returns a list of cases with optional pagination and filtering (limit, offset, tenantid, sort, order, status, min_score). Maximum 500 cases per request.
Stellar Cyber's documentation for this action can be found here.
Get Case Scores
Retrieves case scores for a given case ID.
Stellar Cyber's documentation for this action can be found here.
Retrieve Paginated Alerts
Retrieves paginated alerts for the given case. Use the path parameter Case ID (id) and the query parameters Skip and Limit (maximum 50 per request). Response includes data.docs with alert documents.
Stellar Cyber's documentation for this action can be found here (see Cases β alerts endpoint).
Execute Elasticsearch Job
Performs an Elasticsearch DSL query on a specified index via /connect/api/data/{index}/_search. Only available to Super Admin users with root scope (API key from Generate New Token on System | ORGANIZATION MANAGEMENT | Users); not available for scoped API keys. Use path_parameters.index (e.g. aella-eventsummary-*, aella-ser-*) and json_body for the query DSL.
This action uses the framework's default HTTP runner. When the asset is HTTP Basic Authentication the bearer token is minted by the shared runner_override.http_basic() hook (see the Authentication Methods section above); when the asset is HTTP Bearer Authentication the supplied token is used directly.
Stellar Cyber's documentation for this action can be found here.
List Connectors
Returns a list of connectors in the Stellar Cyber instance.
Stellar Cyber's documentation for this action can be found here.
List Tenants
Returns a list of tenants in the Stellar Cyber instance.
Stellar Cyber's documentation for this action can be found here.
Create Connector
Creates a new connector in the Stellar Cyber instance. Send the connector definition in the JSON body.
Stellar Cyber's documentation for this action can be found here.
List Users
Returns a list of users in the Stellar Cyber instance.
Stellar Cyber's documentation for this action can be found here.
Add Comment to a Case
Adds a comment to an existing case. Provide the case ID in the path and the comment payload in the JSON body.
Stellar Cyber's documentation for this action can be found here.
Update Case
Updates an existing case (status, assignee, tags, etc.). Provide the case ID in the path and the update payload in the JSON body.
Stellar Cyber's documentation for this action can be found here.
Configurations
HTTP Basic Authentication
Authenticates against the Stellar Cyber API with username and password.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target Stellar Cyber host (e.g. https://myserver.stellarcyber.cloud). | string | Required |
username | Stellar Cyber user (typically the account email address). | string | Required |
password | Password for the Stellar Cyber user (or API key when the user authenticates with one). | string | Required |
verify_ssl | Verify SSL certificate. | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
HTTP Bearer Authentication
Authenticates using bearer token such as a JWT, etc.
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
token | The API key, token, etc. | string | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
Actions
Add Comment to a Case
Add a comment to a specified case in Stellar SIEM using the case ID and a comment string. This action requires path parameters and a JSON body.
Endpoint
- URL: /connect/api/v1/cases/{{id}}/comments
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Case ID (path parameter). |
comment | string | Optional | The comment text. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{},"comment":"string"}
Output
Parameter | Type | Description |
|---|---|---|
data | object | The created comment. |
data.comment | string | Response data |
data._id | string | Response data |
data.case_id | string | Response data |
data.created_at | number | Response data |
data.modified_at | number | Response data |
data.user | string | Response data |
Output Example
{"data":{"comment":"string","_id":"string","case_id":"string","created_at":123,"modified_at":123,"user":"string"}}
Create Connector
Create a connector configuration in Stellar SIEM using POST /connect/api/v1/connector with query parameters and JSON body.
Endpoint
- URL: /connect/api/v1/connector
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.update_profile | boolean | Optional | For On-premises only, update DR profile. For SaaS, the API returns 400 when true. Default false. |
parameters.profile | string | Optional | Profile name. Default "Default". |
cust_id | string | Optional | Unique identifier |
name | string | Optional | Name of the resource |
type | string | Optional | Type of the resource |
category | string | Optional | e.g. asset. |
is_collect | boolean | Optional | Parameter for Create Connector |
is_respond | boolean | Optional | Parameter for Create Connector |
run_on | string | Optional | Parameter for Create Connector |
conf | string | Optional | Parameter for Create Connector |
filter_list | array | Optional | Parameter for Create Connector |
advanced_setting | boolean | Optional | Parameter for Create Connector |
Input Example
{"parameters":{"update_profile":true,"profile":"Default"},"cust_id":"string","name":"Example Name","type":"string","category":"string","is_collect":true,"is_respond":true,"run_on":"string","conf":"string","filter_list":["string"],"advanced_setting":true}
Execute Elasticsearch Job
Perform an Elasticsearch DSL query on a specified index in Stellar SIEM via /connect/api/data. Requires Super Admin and root scope access with a new token.
Endpoint
- URL: /connect/api/data/{{index}}/_search
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.index | string | Required | Index pattern (e.g. aella-eventsummary-*). |
Input Example
{"path_parameters":{"index":"string"},"parameters":{}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Output Example
{}
Get Case Scores
Retrieve the case score activities of a given case in Stellar SIEM, returning a list of score activities with reasons and associated alerts. Requires the case ID as a path parameter.
Endpoint
- URL: /connect/api/v1/cases/{{id}}/scores
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Case ID (path parameter). |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"}}
Output
Parameter | Type | Description |
|---|---|---|
data | array | List of case score activity objects. |
data.reasons | array | Score reasons with associated alerts. |
data.reasons.alerts | array | Response data |
data.reasons.alerts.index | string | Response data |
data.reasons.alerts.id | string | Response data |
data.reasons.reason | string | Response data |
data.score | number | Score value. |
data.timestamp | number | Epoch timestamp. |
data.version | number | Response data |
Output Example
{"data":[]}
List Cases
Retrieve a list of existing cases in Stellar SIEM with optional filters and pagination.
Endpoint
- URL: /connect/api/v1/cases
- Method: GET
Input
Argument Name | Type | Required | Description | ||||
|---|---|---|---|---|---|---|---|
parameters.tenantid | string | Optional | Filter by tenant ID. | ||||
parameters.cust_id | string | Optional | Filter by tenant ID (alias). | ||||
parameters.name | string | Optional | Filter by case name. | ||||
parameters.NOT~name | string | Optional | Exclude by case name. | ||||
parameters.ticket_id | number | Optional | Filter by case number. | ||||
parameters.NOT~ticket_id | number | Optional | Parameters for the List Cases action | ||||
parameters.FROM~ticket_id | number | Optional | Parameters for the List Cases action | ||||
parameters.TO~ticket_id | number | Optional | Parameters for the List Cases action | ||||
parameters.score | number | Optional | Filter by case score. | ||||
parameters.NOT~score | number | Optional | Parameters for the List Cases action | ||||
parameters.FROM~score | number | Optional | Parameters for the List Cases action | ||||
parameters.TO~score | number | Optional | Parameters for the List Cases action | ||||
parameters.size | number | Optional | Filter by alert count. | ||||
parameters.NOT~size | number | Optional | Parameters for the List Cases action | ||||
parameters.FROM~size | number | Optional | Parameters for the List Cases action | ||||
parameters.TO~size | number | Optional | Parameters for the List Cases action | ||||
parameters.status | string | Optional | Filter by status (New | In Progress | Escalated | Resolved | Cancelled). |
parameters.NOT~status | string | Optional | Parameters for the List Cases action | ||||
parameters.severity | string | Optional | Filter by severity (Critical | High | Medium | Low). | |
parameters.NOT~severity | string | Optional | Parameters for the List Cases action | ||||
parameters.modified_by | string | Optional | Filter by modifier. | ||||
parameters.NOT~modified_by | string | Optional | Parameters for the List Cases action | ||||
parameters.modified_at | number | Optional | Filter by modification time (epoch ms). | ||||
parameters.NOT~modified_at | number | Optional | Parameters for the List Cases action | ||||
parameters.FROM~modified_at | number | Optional | Parameters for the List Cases action |
Input Example
{"parameters":{"tenantid":"string","cust_id":"string","name":"Example Name","NOT~name":"Example Name","ticket_id":123,"NOT~ticket_id":123,"FROM~ticket_id":123,"TO~ticket_id":123,"score":123,"NOT~score":123,"FROM~score":123,"TO~score":123,"size":123,"NOT~size":123,"FROM~size":123,"TO~size":123,"status":"active","NOT~status":"active","severity":"string","NOT~severity":"string","modified_by":"string","NOT~modified_by":"string","modified_at":123,"NOT~modified_at":123,"FROM~modified_at":123,"TO~modified_at":123,"created_by":"string","NOT~created_by":"string","created_at":123,"NOT~created_at":123,"FROM~created_at":123,"TO~created_at":123,"tags":"string","NOT~tags":"string","assignee":"string","NOT~assignee":"string","event_id":"string","event_index":"string","min_score":123,"min_size_auto":123,"search":"string","queue":"string","skip":123,"limit":123,"sort":"string","order":"string","include_summary":true,"include_details":true,"format_summary":true}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data. |
data.cases | array | List of cases. |
data.cases._id | string | Response data |
data.cases.acknowledged | number | Response data |
data.cases.assignee | string | Response data |
data.cases.closed | number | Response data |
data.cases.created_at | number | Response data |
data.cases.created_by | string | Response data |
data.cases.cust_id | string | Response data |
data.cases.insyncs | array | Response data |
data.cases.insyncs.insync_id | string | Response data |
data.cases.insyncs.insync_name | string | Response data |
data.cases.insyncs.status | string | Response data |
data.cases.insyncs.last_synced_out_time | number | Response data |
data.cases.insyncs.last_synced_in_time | number | Response data |
data.cases.insyncs.error_message | string | Response data |
data.cases.insyncs.source_id | string | Response data |
data.cases.insyncs.source_link | string | Response data |
data.cases.insyncs.type | string | Response data |
data.cases.modified_at | number | Response data |
data.cases.modified_by | string | Response data |
data.cases.name | string | Response data |
data.cases.score | number | Response data |
Output Example
{"data":{"cases":[{}],"total":123}}
List Connectors
Retrieve a list of configured connectors in Stellar SIEM, optionally filtered by tenant using cust_id.
Endpoint
- URL: /connect/api/v1/connector
- Method: GET
Input
Argument Name | Type | Required | Description | ||
|---|---|---|---|---|---|
parameters.cust_id | string | Optional | Optional. Get all connectors assigned to a specified tenant. cust_id can be retrieved from System | Administration | Tenants page. |
Input Example
{"parameters":{"cust_id":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
total | number | Total count of connectors. |
connectors | array | List of connector objects. |
connectors._id | string | Unique identifier |
connectors.category | string | Output field: connectors.category |
connectors.configuration | string | Output field: connectors.configuration |
connectors.tenantid | string | Unique identifier |
connectors.is_collect | boolean | Output field: connectors.is_collect |
connectors.is_respond | boolean | Output field: connectors.is_respond |
connectors.name | string | Name of the resource |
connectors.run_on | string | Output field: connectors.run_on |
connectors.type | string | Type of the resource |
connectors.version | string | Output field: connectors.version |
connectors.last_activity | string | Output field: connectors.last_activity |
connectors.last_data_received | string | Response data |
connectors.status | string | Status value |
connectors.active | boolean | Output field: connectors.active |
connectors.filter_list | array | Output field: connectors.filter_list |
connectors.created_at | number | Output field: connectors.created_at |
connectors.modified_at | number | Output field: connectors.modified_at |
Output Example
{"total":123,"connectors":[]}
List Tenants
Retrieve the list of existing tenants in Stellar SIEM with optional query fields for specific data inclusion.
Endpoint
- URL: /connect/api/v1/tenants
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.fields | string | Optional | Optional comma-separated list of fields to include in response (e.g., "cust_id,cust_name"). |
Input Example
{"path_parameters":{},"parameters":{"fields":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
data | array | List of tenant objects. |
data.org_id | string | Response data |
data.cust_name | string | Response data |
data.cust_id | string | Response data |
data.ds_num | number | Response data |
data.user_num | number | Response data |
data.tgrp_name | string | Response data |
data.contact | string | Response data |
data.contact_email | string | Response data |
data.contact_phone | string | Response data |
data.address | string | Response data |
data.daily_limit | number | Response data |
data.info | string | Response data |
data.retention_group | string | Response data |
data.mfa_enabled | boolean | Response data |
data.authentication_method | string | Response data |
data.sso_config | string | Response data |
data.ingestion_limit | number | Response data |
data.tenant_session_override | boolean | Response data |
data.session_timeout | number | Response data |
data.message | string | Response data |
data.created_at | number | Response data |
data.modified_at | number | Response data |
Output Example
{"data":[]}
List Users
Retrieve the list of existing users in Stellar SIEM with an optional cust_id query to filter the results.
Endpoint
- URL: /connect/api/v1/users
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.cust_id | string | Optional | Filter the list by cust_id (tenant). |
Input Example
{"path_parameters":{},"parameters":{"cust_id":"string"}}
Output
Parameter | Type | Description |
|---|---|---|
data | array | List of user objects. |
data.created_at | number | Response data |
data.created_by | string | Response data |
data.modified_at | number | Response data |
data.modified_by | string | Response data |
data.cust_id | string | Response data |
data.default | boolean | Response data |
data.display_name | string | Response data |
data.email | string | Response data |
data.email_notify | boolean | Response data |
data.language | string | Response data |
data.mfa_enabled | boolean | Response data |
data.name | string | Response data |
data.phone | string | Response data |
data.priv_profile_id | string | Response data |
data.query | string | Response data |
data.user_role | string | Response data |
data.tgrp_id | string | Response data |
data.homepage | object | Response data |
data.homepage.url | string | Response data |
data.homepage.alias | string | Response data |
data.cdp | boolean | Response data |
data.duplicate | object | Response data |
data.duplicate.name | boolean | Response data |
data.duplicate.email | boolean | Response data |
Output Example
{"data":[]}
Retrieve Paginated Alerts
Retrieve a specified range of alerts for a case in Stellar SIEM using the case ID, with options to skip and set a limit up to 50 alerts per request.
Endpoint
- URL: /connect/api/v1/cases/{{id}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Case ID (path parameter). |
parameters.skip | number | Required | Number of records to skip before returning results. E.g. skip=10&limit=10 returns the second 10 alerts. |
parameters.limit | number | Required | Maximum number of results to return. A maximum of 50 results can be returned at a time. E.g. limit=10 returns the first 10 alerts. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{"skip":123,"limit":123}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
data | object | Response data |
data.docs | array | Response data |
data.docs._version | number | Response data |
data.docs._type | string | Response data |
data.docs._source | object | Response data |
data.docs._seq_no | number | Response data |
data.docs._primary_term | number | Response data |
data.docs._index | string | Response data |
data.docs._id | string | Response data |
data.docs.found | boolean | Response data |
Output Example
{"status_code":200,"reason":"OK","json_body":{"data":{"docs":[]}}}
Update Case
Update a specific case in Stellar SIEM using its ID with details like name, severity, status, assignee, tags, and resolution.
Endpoint
- URL: /connect/api/v1/cases/{{id}}
- Method: PUT
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Case ID (path parameter). |
name | string | Optional | Case name (max length 200). |
severity | string | Optional | Critical, High, Medium, or Low. |
status | string | Optional | Escalated, New, In Progress, Resolved, or Cancelled. |
assignee | string | Optional | Assignee username. |
tags | object | Optional | Add or delete tags. |
tags.delete | array | Optional | Tags to remove. |
tags.add | array | Optional | Tags to add. |
update_alerts | boolean | Optional | Whether to update associated alerts. |
resolution | string | Optional | False Positive, Benign, or True Positive. |
Input Example
{"path_parameters":{"id":"12345678-1234-1234-1234-123456789abc"},"parameters":{},"name":"Example Name","severity":"string","status":"active","assignee":"string","tags":{"delete":["string"],"add":["string"]},"update_alerts":true,"resolution":"string"}
Output
Parameter | Type | Description |
|---|---|---|
data | object | Updated case object. |
data._id | string | Response data |
data.acknowledged | number | Response data |
data.assignee | string | Response data |
data.closed | number | Response data |
data.created_at | number | Response data |
data.created_by | string | Response data |
data.cust_id | string | Response data |
data.insyncs | array | Response data |
data.insyncs.insync_id | string | Response data |
data.insyncs.insync_name | string | Response data |
data.insyncs.status | string | Response data |
data.insyncs.last_synced_out_time | number | Response data |
data.insyncs.last_synced_in_time | number | Response data |
data.insyncs.error_message | string | Response data |
data.insyncs.source_id | string | Response data |
data.insyncs.source_link | string | Response data |
data.insyncs.type | string | Response data |
data.modified_at | number | Response data |
data.modified_by | string | Response data |
data.name | string | Response data |
data.score | number | Response data |
data.size | number | Response data |
data.status | string | Response data |
data.resolution | string | Response data |
Output Example
{"data":{"_id":"string","acknowledged":123,"assignee":"string","closed":123,"created_at":123,"created_by":"string","cust_id":"string","insyncs":[{}],"modified_at":123,"modified_by":"string","name":"Example Name","score":123,"size":123,"status":"active","resolution":"string"}}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |