[Integration] CC integrate ES SAAS
Issue Description
CC unable to integrate with SAAS ES
Error/Warning Information
Chose NDR on platform x instead of SIP, causing integration error.
Handling Process
-
Platform X → make sure SAAS ES is online, add device as SIP using manual input (enable EDR)

-
Enable integration on ES SAAS for 1440 minutes

-
Cybercommand → add device as SAAS ES but using auth from SIP

-
Check ES SAAS will automatically integrate with CC

-
Add SIP auth from platform x into cyber command response app (CC will only appear as online after it is added to response app)

-
Test connectivity

Root Cause
Due to limiteation on Platform X, for CC integrate with ES SAAS must use SIP and manual input.
Solution
Use SIP instead of NDR.
Reference
NA