matanolabs / matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
https://matano.dev
Apache License 2.0
1.46k stars 100 forks source link

Managed log source for Signal Sciences audit logs #56

Open timoguin opened 1 year ago

timoguin commented 1 year ago

Add support for managing audit logs from Signal Sciences.

Considerations

Signal Sciences has two types of audit logs:

Currently, only the site audit logs can be streamed in a useful way, via generic webhooks.

Corp audit logs, which may arguably be more useful, can only be sent to email, Microsoft Teams, or Slack. I have an open feature request (pre-Fastly acquisition) for webhook support that is several years old and seems to have gotten lost in the ether a few times, despite several follow-ups with account reps and TAMs. 😞

Tasks

References