Setting Up SOAR to Receive Alerts

Select RESPONDConfiguration.

To ensure seamless security resilience, you must configure SOAR solution to receive alerts from disparate security tools and platforms.

You must create a user credential in the Credential tab to communicate with other components. After a credential is created, you must add the alert source in the SOAR platform. Every alert in SOAR is generated through a rule in the alert source and whenever an alert is received by SOAR, it is received with the rules that were used to process the alerts.

After the Alert source is added, you must integrate the component with SOAR in the Integration tab.

You can enable additional configuration parameters for enrichment or to forward events by other component on a specific port number or any other configuration in the Parameters tab.