sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:3eb2ee456cd0b9a4d5ff28c084cfd72e8916af088fcf0f823ec2d2d7b6110e7e
Ships sandbox observability (process, network, file, and agent-activity logs) to a SIEM HTTP event collector for dashboards, correlation, and automated response. Closes the visibility gap for what runs inside the sandbox.
| Name | Required | Default | Description |
|---|---|---|---|
siemCollectorAuthId | Optional | | Cortex XSIAM HTTP Collector API key ID (numeric, non-secret), sent as the x-xdr-auth-id header alongside the Authorization token. XSIAM requires both; leave empty for collectors that authenticate with the Authorization header alone. |
siemCollectorHost | Optional | siem-collector.example.com | SIEM HTTP event collector ingestion host (FQDN, no scheme). Defaults to a placeholder; set it to your collector or telemetry has nowhere to ship. |
siemCollectorPath | Optional | /logs/v1/event | HTTP path on the collector to POST events to. |
| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-panw-siem-telemetry:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbx