Skip to content

APPSINTG-52:DFIR-IRIS Integration - Documentation - #7015

Open
shreyashnaik-sumo wants to merge 2 commits into
SumoLogic:mainfrom
shreyashnaik-sumo:APPSINTG-52
Open

APPSINTG-52:DFIR-IRIS Integration - Documentation#7015
shreyashnaik-sumo wants to merge 2 commits into
SumoLogic:mainfrom
shreyashnaik-sumo:APPSINTG-52

Conversation

@shreyashnaik-sumo

@shreyashnaik-sumo shreyashnaik-sumo commented Aug 13, 2026

Copy link
Copy Markdown
Collaborator

Purpose of this pull request

Implements a new DFIR-IRIS integration for Cloud SOAR, including connection setup and a set of actions to manage IRIS cases/alerts and related artifacts (IOCs, assets, notes, timeline events).
Changes:
Added the DFIR-IRIS integration definition with test connection logic and configuration fields.
Added case-centric actions (create/get/list/update/close, list/add IOCs, add assets).
Added alert and collaboration actions (create alert, escalate alert to case, add note, add timeline event).

Select the type of change

  • Minor Changes - Typos, formatting, slight revisions
  • Update Content - Revisions, updating sections
  • New Content - New features, sections, pages, tutorials
  • Site and Tools - .clabot, version updates, maintenance, dependencies, new packages for the site (Docusaurus, Gatsby, React, etc.)

Ticket (if applicable)

https://sumologic.atlassian.net/browse/APPSINTG-52

@cla-bot cla-bot Bot added the cla-signed Contributor approved, listed in .clabot file label Aug 13, 2026

@amee-sumo amee-sumo left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Clean, well-structured addition. Verified the doc closely matches sibling API-key-based integrations (arcanna.md, abnormal-security.md) in section order and conventions — correctly omits the AWS-specific External Libraries/Required Permissions sections since this isn't a boto3 integration. Actions list is properly alphabetized (12 items), action type tags (Notification vs. Enrichment) are used consistently with the rest of the repo, all internal anchors resolve, and asset paths match their references. No blockers.

Minor, non-blocking: the version banner and Change Log both say "August 14, 2026" — a day ahead of today, likely just the intended publish date.

Approving.

@shreyashnaik-sumo

shreyashnaik-sumo commented Aug 13, 2026 via email

Copy link
Copy Markdown
Collaborator Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed Contributor approved, listed in .clabot file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants