Apps
LogRhythm
Interpres Application - LogRhythm
- Type: SIEM/Data Lake
- Vendor: LogRhythm
This app integrates with LogRhythm to get Telemetry & Alerts. Detections need to be manually uploaded.
- Log in to the Client Console as a Global Administrator, click Deployment Manager, and then click the Third Party Applications tab.
- Click New in the main toolbar and provide the Application Name and Description for the token.
- Return to the Third Party Applications tab, and double-click the application you created. Click Generate Token.
- Click OK, and then click Copy Token.
For more detailed instructions go to https://docs.logrhythm.com/lrsiem/7.12.0/generate-lr-api-token
- base url: The URL To the api source instance. The format is https://{IP}:8501
- verify server cert: If enabled Interpres will verify the SSL certificate
- access token: Token to access LogRhythm API
Check there is connectivity (green light) in the integration created.
- get_available_telemetry: Returns a list of telemetry identifiers with their current status.
- get_alerts: Gets the latest alerts.
- get_detections: Detections need to be uploaded manually. Please contact Interpres Customer support if you need help.