Sysdig · Arazzo Workflow
Sysdig Investigate Secure Event
Version 1.0.0
List secure runtime events, branch on a match, and pull the activity audit.
View Spec
View on GitHub
Cloud SecurityContainersKubernetesRuntime SecuritySecurityVulnerability ManagementMonitoringObservabilityCSPMComplianceArazzoWorkflows
Provider
Workflows
investigate-secure-event
Surface secure events and correlate them with the activity audit.
Lists secure events in a time window; if any are present, retrieves the activity audit for the same window to correlate context.
1
listEvents
listSecureEvents
Retrieve secure runtime events within the time window.
2
correlateAudit
listActivityAudit
Retrieve the activity audit trail across the same time window.