Watching the system
Integrations: webhooks, Splunk and syslog
Send security events to your SIEM or chat tools.
| Kind | Notes |
|---|---|
| Webhook | https only. With a secret of 16 or more characters, each request carries x-forgerepo-signature: sha256=<HMAC of timestamp.body> and x-forgerepo-timestamp. |
| Splunk HEC | https only. The HEC token is the secret. |
| Syslog | tls, tcp or udp, JSON or CEF. Port 6514 by default for tls. |
Pick events such as package.blocked, package.quarantined, malware.detected, vulnerability.discovered, artifact.integrity_changed, waiver.created and policy.violation, or every event. Deliveries retry with backoff for up to 10 attempts. Use test to send one now and deliveries to see what happened.
Note
Addresses on the server itself and cloud metadata addresses are refused, and redirects are not followed.