Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix_semantic #1809

Merged
merged 2 commits into from
Jun 4, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 15 additions & 11 deletions docs/xdr/FAQ.md
Original file line number Diff line number Diff line change
@@ -1,20 +1,22 @@
# IP
# FAQ

## Is the IP behind `intake.sekoia.io` static?
## IP

### Is the IP behind `intake.sekoia.io` static?

**IP for `intake.sekoia.io` is `51.159.9.95`.**

`intake.sekoia.io` is the domain name used to send your logs to Sekoia.io, either via Syslog or HTTP protocols. The IP address behind that service is static and stable. You can use that IP to configure your firewalls to allow connections from your forwarding systems to Sekoia.io.

## Outgoing IP addresses for playbooks runs and connectors
### Outgoing IP addresses for playbooks runs and connectors


For all the actions available in the Playbooks section of Sekoia.io (include connectors used to retrieve logs from external sources), we use a number of outbound IP addresses. The full list is publicly accessible and can be retrieved at the following URL: [https://api.sekoia.io/outgoing-ips](https://api.sekoia.io/outgoing-ips). This will be useful to setup filtering options if needed, and even automate any future update.

We try to make this list as stable as possible, but events out of our control may result in modifications. If any changes occur, we are committed to providing our customers with advance notice of at least two weeks, either via a dedicated communication, or via our [status page](https://status.sekoia.io/).


## How to debug Rsyslog’s forward configuration to Sekoia.io?
### How to debug Rsyslog’s forward configuration to Sekoia.io?

If you use Rsyslog to forward your logs to Sekoia.io, you will probably have a section like this in your configuration files:

Expand All @@ -39,11 +41,13 @@ This way, you will be able to exactly identify what data is sent to Sekoia.io.
```


# Logs
## Retention
Logs are available and displayed for 90 days in Sekoia.io.
## Logs

### Retention

Logs are available and displayed for 30 days in Sekoia.io, for standard contracts.

## Archive and restore data
### Archive and restore data

!!! Info

Expand All @@ -52,7 +56,7 @@ Logs are available and displayed for 90 days in Sekoia.io.
Option not available for all plans


### Restoration process :
**Restoration process**

- The request must be made to [[email protected]](mailto:[email protected])

Expand All @@ -62,6 +66,6 @@ Logs are available and displayed for 90 days in Sekoia.io.

- Restored data will be deleted after 30 days

### Restoration flow:
**Restoration flow**

<img style="max-width:100%" alt="Archiving diagram" src="/xdr/FAQ/archiving_process.png">
<img style="max-width:100%" alt="Archiving diagram" src="/xdr/FAQ/archiving_process.png">
Loading