Sign inSign up

docker/sbx-kit-panw-siem-telemetry:1.0.0

Multi-platform
Manifest digest

sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e

MIXIN

Ships sandbox observability (process, network, file, and agent-activity logs) to a SIEM HTTP event collector for dashboards, correlation, and automated response. Closes the visibility gap for what runs inside the sandbox.


Arguments
NameRequiredDefaultDescription
siemCollectorAuthIdOptional

Cortex XSIAM HTTP Collector API key ID (numeric, non-secret), sent as the x-xdr-auth-id header alongside the Authorization token. XSIAM requires both; leave empty for collectors that authenticate with the Authorization header alone.

siemCollectorHostOptionalsiem-collector.example.com

SIEM HTTP event collector ingestion host (FQDN, no scheme). Defaults to a placeholder; set it to your collector or telemetry has nowhere to ship.

siemCollectorPathOptional/logs/v1/event

HTTP path on the collector to POST events to.


CapabilitiesExpand a row to see its full configuration.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-panw-siem-telemetry:1.0.0

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠