The TruSTAR LogRhythm integration saves you time by automatically sending alerts to the TruSTAR platform for additional enrichment with other intelligence sources. If you prefer to query TruSTAR enrichment data directly from the LogRhythm Threat Intelligence Service platform, that is possible as well.
The TruSTAR LogRhythm integration enables:
LogRhythm events are shown as nodes within TruSTAR’s graph analysis view so that you can easily explore correlations between your events and your other intelligence sources. Click on any data point to reveal additional context that links directly to the associated report in your LogRhythm portal, allowing for easy additional research when needed.
TruSTAR’s robust STIX/TAXII compatibility enables the integration with LogRhythm’s Threat Intelligence Service. Since TruSTAR data is discoverable thought a TAXII service endpoint, LogRhythm users can take full advantage of TruSTAR’s high-quality intelligence data natively in-app. TruSTAR also has a SmartResponse module to send events to the platform for additional enrichment.