Security Operations LogRhythm Integration
Create security response incidents automatically from LogRhythm Enterprise alarms.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 22 | -22 |
| 13 days of no change | ||
| 2026-04-13 | 23 | -1 |
| 5 days of no change | ||
| 2026-04-07 | 24 | -1 |
| 10 days of no change | ||
| 2026-03-27 | 25 | -1 |
| 55 days of no change | ||
| 2026-01-30 | 26 | -1 |
About
The Security Operations LogRhythm integration allows Security Operations Center (SOC) analysts to automatically generate Security Incident Response (SIR) incidents when certain configured LogRhythm alarms are triggered. The SOC analyst responds to the incidents using workflows that automate incident response activities and close out the LogRhythm alarms after closing the SIR incident.
Key Features
The integration includes the following key features:
- Flexibility to create multiple alarm profiles such as phishing and malware.
- Drag-and-drop mapping of LogRhythm alarm field values to associated SIR security incident fields.
- A preview of the SIR security incident layout based on sample alarms to validate configuration setup.
- Ingest historical alarms as well as ongoing, future alarms on configurable intervals.
- Automated alarm closeout upon incident closure, which includes a SIR security incident ID and URL for easy linking.