Security Vision IRP handler
The Security Vision IRP handler receives KUMA alert data from the Security Vision IRP connector and creates Security Vision IRP incidents based on this data. A predefined KUMA (Инциденты) (KUMA (Incidents)) handler is used for processing data. The settings of the KUMA (Инциденты) (KUMA (Incidents)) handler are available in Security Vision IRP under Настройки (Settings) → Обработка событий (Event processing) → Обработчики событий (Event handlers):
Handler run schedule
The connector and handler are started according to a predefined KUMA schedule. This schedule can be configured in Security Vision IRP under Настройки (Settings) → Обработка событий (Event processing) → Расписание (Schedule):
Security Vision IRP worker process
The life cycle of Security Vision IRP incidents created based on KUMA alerts follows the preconfigured Incident processing (2 lines) worker. The worker can be configured in Security Vision IRP under Settings → Workers → Worker templates: select the Incident processing (2 lines) worker and click the transaction or state that you need to change.
Page top