Integrating Cloud SOAR with Secret Server
This integration connects Delinea Secret Server to the Sumo Logic Automation Service and Cloud SOAR, so that security analysts can act on privileged credentials as part of an automated response.
In Sumo Logic, a playbook is a workflow of actions that runs in response to an event, such as an insight raised by Cloud SIEM. This integration adds Secret Server actions to those playbooks. An analyst can retrieve the details of a secret to identify the affected credential, or contain a compromised credential by checking it out, expiring it, or deleting it, without opening Secret Server.
The integration installs from App Central and requires the URL of your Secret Server instance, a client ID, and a client secret. Actions run on Sumo Logic's cloud execution engine (bridge and proxy options apply only to custom integrations).
This integration offers the following benefits:
-
Analysts contain a compromised credential as a step in the response workflow, rather than as a separate manual task in another console.
-
Incidents carry the details of the affected secret, so analysts can identify the credential before deciding what to do.
-
Credential operations are defined in a playbook, so the response is consistent and recorded alongside the rest of the incident.
This third-party integration does not natively support the Delinea Platform (Secret Server on the Delinea Platform). Once upgraded to the Delinea Platform, the integration will continue to function properly as long as the application account used for the integration remains in Secret Server. Once fully upgraded to the Delinea Platform service account model, the existing integration will no longer work with Secret Server on the Delinea Platform as all identity data will be moved to the Delinea Platform and will no longer be maintained in Secret Server.
To learn more about this integration, see the Sumo Logic integration with Delinea Secret Server documentation.