Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update xdr_quick_start.md #1716

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions docs/xdr/xdr_quick_start.md
Original file line number Diff line number Diff line change
Expand Up @@ -16,8 +16,6 @@ An Entity is an organizational unit mostly used for configuration and reporting
1. Go to the Entities page and create an Entity.
2. Select the `Alert generation` mode of your choice. We suggest you to select “Automatic” which will simplify the workflow of alert management for you. More details [here](https://docs.sekoia.io/xdr/features/collect/entities/).

![entities](/assets/operation_center/quick_start/entities.png){: style="max-width:100%"}

### Create intakes

The Intakes correspond to the different technologies used (also called Data Sources) that forward their logs to Sekoia.io XDR to be centralized for security monitoring. You can configure as much intakes as you need to increase your infrastructure security with Sekoia.io knowledge.
Expand All @@ -30,17 +28,13 @@ To create intakes associated to the technology you would like to collect:
!!! note
Find more details on each integration in our [integrations catalog](https://docs.sekoia.io/xdr/features/collect/integrations/).

![intakes](/assets/operation_center/quick_start/intakes.png){: style="max-width:100%"}

### Activate detection rules

Once your event logs are collected and normalized by Sekoia.io, you probably want to leverage them to detect suspicious activity within your perimeter. Rules contain the detection logic that determines when Alerts should be created.

1. Enable all detection rules of effort levels 1 or 2 by filtering on each effort level then clicking on the `Enable all` button.
2. Automate the activation of future detection rules with the same effort levels following [this procedure](https://docs.sekoia.io/xdr/features/detect/rules_catalog/#enable-new-rules).

![rules](/assets/operation_center/quick_start/rules.png){: style="max-width:100%"}

**That’s it!**

### And then what?
Expand Down
Loading