Skip to content

Add the BlackNoise AEV intake documentation - #3174

Draft
Remi-eri wants to merge 6 commits into
SEKOIA-IO:mainfrom
Remi-eri:feat/blacknoise-aev-doc
Draft

Add the BlackNoise AEV intake documentation#3174
Remi-eri wants to merge 6 commits into
SEKOIA-IO:mainfrom
Remi-eri:feat/blacknoise-aev-doc

Conversation

@Remi-eri

Copy link
Copy Markdown

Document the BlackNoise AEV intake: intake creation on Sekoia, forwarding configuration on the BlackNoise side, and the reverse connector that reads Sekoia alerts back so an adversarial action carries whether it was detected.

The page pairs with the format contributed in SEKOIA-IO/intake-formats.

Document the BlackNoise AEV intake: intake creation on Sekoia, forwarding
configuration on the BlackNoise side, and the reverse connector that reads
Sekoia alerts back so an adversarial action carries whether it was detected.

The page pairs with the format contributed in SEKOIA-IO/intake-formats.
@Remi-eri
Remi-eri marked this pull request as draft August 14, 2026 09:49
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown

Newest code from Remi-eri has been published to preview environment

🚀 Latest deployment was built on 2026-08-14 13:46:16 (20985f806eb5a30befae8fd687a739a1247d54c9).

The connector only pushes to the intake: drop the API key section that
described reading Sekoia alerts back, and follow the real order of the
setup — API URL first, then the intake, then the intake key.

Fix the console paths and labels (Resources > Connectors, Configure,
Edit connector), document the batch endpoint the connector posts to and
the addresses it derives from the API URL, and replace the manual curl by
the connection test, which already ingests a healthcheck event.
Drop the generated sample, detection and suggested-rules includes, along
with the wording that called the BlackNoise interface a console, and say
which catalog the format is searched in.
Raw event samples, ECS fields and suggested rules are regenerated from
intake-formats by the update-intakes-documentation workflow. Every intake
page carries them.
@Remi-eri
Remi-eri marked this pull request as ready for review August 14, 2026 13:57
@Remi-eri
Remi-eri marked this pull request as draft August 14, 2026 13:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant