SIEM integration
Automate Exabeam Security Operations SIEM with plain language
Read Exabeam notable users, alerts and cases, and add context from VernacSecure SuperBot™ to an investigation.
What you can do
Exabeam — Security Operations Platform REST API
- List notable users and sessions
- Read alerts and cases
- Add a comment to a case
Connection: bearer authentication against https://api.us-west.exabeam.cloud. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Show the last 24 hours of high severity alerts in Exabeam Security Operations”
Result: VernacSecure SuperBot™ runs the search, normalises the results and offers follow-up actions on other integrations.
Read actions
- Fetch notable users — Lists users with the highest risk scores.
- Fetch alerts — Lists alerts.
- Fetch cases — Lists incident cases.
Write actions
This integration is read-only today. Write actions are added upstream as the vendor API exposes them.
Related siem automation pages
Armor Point · Datadog Cloud SIEM · Devo Platform · Elastic Security · Fortinet FortiSIEM · Google Security Operations (Chronicle)