Swimlane VRM Enrichment
Swimlane VRM Enrichment automates the enrichment, correlation, and export of vulnerability findings to optimize vulnerability risk management workflows.
Swimlane VRM Enrichment extends Swimlane Turbine with advanced vulnerability risk management capabilities. This connector enables automated enrichment, grouping, and prioritization of vulnerability findings by leveraging intelligence caches, custom risk scoring, and bulk data processing. Users can seamlessly export, stage, and enrich vulnerability data from multiple sources, accelerating triage and remediation workflows. Integration with Swimlane VRM Enrichment empowers security teams to automate vulnerability lifecycle management, reduce manual effort, and improve risk-based decision-making within their low-code security automation environment.
Prerequisites
To use the Swimlane VRM Enrichment connector, ensure you have the following prerequisites configured:
- Swimlane tenant and VRM application configuration for enrichment connector actions, requiring:
- Page Size: Number of records to process per page during ingestion or export.
- Account ID: Unique identifier for the Swimlane account used for API access.
- Tenant ID: Identifier for your Swimlane tenant environment.
- Host: The base URL or hostname of your Swimlane instance.
- Private Access Token: Secure token for authenticating API requests to Swimlane.
- Assets Application Name: Name of the Swimlane application managing asset records.
- Exceptions Application Name: Name of the application handling exception records.
- Findings Application Name: Name of the application where vulnerability findings are stored.
- Ingestion Pages Application Name: Name of the application tracking ingestion pages.
- Staged Ingestion Application Name: Name of the application for staged ingestion records.
- Export Findings & Assets Application Name: Name of the application used for exporting findings and assets.
- Export Findings & Assets Record ID: Identifier for the specific record to be exported.
- Grouping Parameters: Criteria used to group findings or assets during processing or export.
Capabilities
This Connector provides the following capabilities:
- Capabilities
- Go
- Here
- e.g. Manage Firewall Policies instead of listing each individual tasks
Limitations
Include information about known limitations here, including supported or minimum versions, especially known unsupported versions.
Asset Setup
The content here should discuss asset setup in a conversational manner. Be sure to include any known login and test connection errors.
Tasks Setup
Special task setup as needed depending on plugin, exclude if empty.
Known available allowed input options from enum type selection
Notes
- Any other notes not fitting other sections go here.
- Any reference URLs to external docs or other resources
Configurations
VRM Client Configuration
Swimlane tenant and VRM application configuration for enrichment connector actions.
Configuration Parameters
Parameter | Description | Type | Required | ||||
|---|---|---|---|---|---|---|---|
page_size | The number of incoming findings to store in a Staging Record | integer | Required | ||||
account_id | The Swimlane account ID | string | Required | ||||
tenant_id | The Swimlane tenant ID | string | Required | ||||
host | The Swimlane host (e.g., stage.swimlane.app) | string | Required | ||||
pat | The private access token for API authentication | string | Required | ||||
assets_app | The name of the Assets application | string | Required | ||||
exceptions_app | The name of the Exceptions application | string | Required | ||||
findings_app | The name of the Findings application | string | Required | ||||
ingestion_pages_app | The name of the Ingestion Pages application | string | Required | ||||
staged_ingestion_app | The name of the Staged Ingestion application | string | Required | ||||
export_findings_app | The name of the VRM Export Findings & Assets application | string | Required | ||||
export_findings_assets_record_id | Tracking ID of the export record holding Export Findings and Export Assets CSV attachments (e.g. VEF-1) | string | Required | ||||
swimlane_intelligence_bulk_batch_size | Number of CVE IDs per Intelligence bulk API request in populate_swimlane_intelligence_cache. Lower values (e.g. 100β200) reduce memory use on 512 MB connector pods. | integer | Optional | ||||
risk_score_parameters | JSON string containing risk score parameter definitions (weights, max values, keys, etc.) | string | Optional | ||||
grouping_parameters | Required JSON string with ordered grouping rules (type numeric | string | string_array | boolean | presence, literal right_operand values). Rules are maintained offline and must be set on the VRM Client Configuration asset. | string | Required |
Actions
Enrich Findings
Enhance findings by leveraging the Swimlane Intelligence cache, exported VRM findings and assets CSVs, and incoming findings on the VRM Staged Ingestion record.
Endpoint
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
staging_record_id | string | Required | The tracking ID or record ID of the staging record to process (e.g. VSI-5) |
concurrency | integer | Optional | Maximum number of concurrent API calls (default 10) |
batch_size | integer | Optional | Number of records per bulk create API call (default 50). Only applies when batching is enabled. Uses POST /v2/record/bulk. |
use_batching | boolean | Optional | Use the v2 bulk record ingest API for creating new findings (much faster). Set to false to use individual creates. Failed records are retried via failedRecordIds. |
turbine_risk_score_floor_value | number | Optional | New findings are created only when vulnerability-finding-turbine-risk-score is strictly greater than this value. Existing findings are still updated regardless. Default is 0. |
Input Example
{"staging_record_id":"string","concurrency":10,"batch_size":50,"use_batching":true,"turbine_risk_score_floor_value":123}
Output
Parameter | Type | Description |
|---|---|---|
status | string | Outcome of the enrichment process (success or error) |
error | string | Error message when status is error |
findings_processed | number | Number of findings processed |
findings_successful | number | Total findings successfully written (created + updated) |
findings_created | number | Number of new findings created in Swimlane |
findings_updated | number | Number of existing findings updated in Swimlane |
findings_skipped | number | Number of findings skipped |
findings_ignored | number | Number of new findings not created because vulnerability-finding-turbine-risk-score was at or below turbine_risk_score_floor_value |
findings_failed | number | Number of findings that failed |
failed_findings_file | array | JSON file containing findings that failed enrichment |
failed_findings_file.file | string | The file ID |
failed_findings_file.file_name | string | The filename |
Output Example
{"status":"string","error":"string","findings_processed":123,"findings_successful":123,"findings_created":123,"findings_updated":123,"findings_skipped":123,"findings_ignored":123,"findings_failed":123,"failed_findings_file":[]}
Export All Records
Export all records from a specified Swimlane application to a CSV or gzip-compressed CSV file, replicating the native Export Record functionality for use in connector playbooks.
Endpoint
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
application_name | string | Required | Name of the Swimlane application to export records from |
filtered_fields | array | Optional | Field keys to include as CSV columns. When empty, all application fields are exported. |
is_compressed | boolean | Optional | When true (default), output is a gzip-compressed CSV (.csv.gz). When false, output is a plain CSV file. |
Input Example
{"application_name":"Example Name","filtered_fields":["string"],"is_compressed":true}
Output
Parameter | Type | Description |
|---|---|---|
status | string | Outcome of the export (success or error) |
error | string | Error message when status is error |
application_name | string | Resolved application name |
application_id | string | Application ID that was exported |
record_count | number | Number of records exported |
is_compressed | boolean | Whether the export file is gzip-compressed |
export_file | array | Exported CSV or gzip-compressed CSV attachment for downstream playbook use |
export_file.file | string | Turbine file URN (or base64 when running locally without IPC) |
export_file.file_name | string | Export filename (.csv or .csv.gz) |
export_filename | string | Filename of the exported attachment |
export_size_bytes | number | Size of the exported file in bytes |
field_count | number | Number of columns exported |
progress_log | array | Action progress messages |
Output Example
{"status":"string","error":"string","application_name":"string","application_id":"string","record_count":123,"is_compressed":true,"export_file":[],"export_filename":"string","export_size_bytes":123,"field_count":123,"progress_log":[]}
Populate Swimlane Intelligence Cache
Populate the vulnerability intelligence cache using bulk CVE lookups from a staging record and return compressed cache files for playbook upsert.
Endpoint
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
staging_record_id | string | Required | The tracking ID or record ID of the staging record to process |
Input Example
{"staging_record_id":"string"}
Output
Parameter | Type | Description |
|---|---|---|
status | string | Outcome of the cache population process (success or error) |
error | string | Error message when status is error |
swimlane_intelligence_cache_file | array | Compressed Swimlane Intelligence cache file(s) for playbook upsert (may be split into multiple parts if >512MB) |
swimlane_intelligence_cache_file.file | string | Turbine file URN for upsert attachment field |
swimlane_intelligence_cache_file.file_name | string | The filename (e.g. swimlane_intelligence_cache.db.gz) |
staging_record_id | string | Tracking ID of the staging record that was processed |
total_findings_count | number | Total number of findings that have CVE IDs |
findings_failed_metadata_count | number | Number of findings that failed metadata enrichment |
findings_failed_exploit_count | number | Number of findings that failed exploit enrichment |
populated_count | number | Number of CVE IDs successfully cached |
failed_exploit_ids | array | List of CVE IDs that failed exploit lookup |
failed_metadata_ids | array | List of CVE IDs that failed metadata lookup |
cache_storage_filename | string | Filename of the compressed cache file |
Output Example
{"status":"string","error":"string","swimlane_intelligence_cache_file":[],"staging_record_id":"string","total_findings_count":123,"findings_failed_metadata_count":123,"findings_failed_exploit_count":123,"populated_count":123,"failed_exploit_ids":[],"failed_metadata_ids":[],"cache_storage_filename":"string"}
Stage Enrichment
Read ingestion pages and create a staging record in Swimlane VRM Enrichment for further processing.
Endpoint
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
status | string | The status of the enrichment staging run |
staging_record_id | string | Tracking ID of the created VRM Staged Ingestion record (e.g. VSI-5) |
findings_collected | number | Number of findings collected from ingestion pages |
remaining_findings | number | Number of findings written back to the last ingestion page |
error | string | Error message when the action fails |
Output Example
{"status":"string","staging_record_id":"string","findings_collected":123,"remaining_findings":123,"error":"string"}
Response Headers
Header | Description | Example |
|---|---|---|
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 01 Jan 2024 00:00:00 GMT |