01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| Alert IP Triage & Auto-Close |
| 100.0% | 1 1 active |
| Total | 5 executions | 100% | 1 1 active |
Use Case Growth Over Time
03Integration Ecosystem
No integration data found — ensure the CSV contains an actions column.
04Key Observations
Strengths: The deployed playbook automates a real first-pass triage decision (auto-close on fully-known IP ranges), directly reducing analyst noise for Coralogix-sourced alerts.
Gaps: Sandbox SRC currently has a single automated use case with low execution volume (5 runs/12 months), indicating an early-stage deployment. There is no coverage yet for other SOC subcategories (case management, EDR containment, phishing response, identity threat response) or other pillars (Cloud Security, Vulnerability Mgmt, GRC, IAM).
- Integration ecosystem: The workflow pairs Coralogix as the alerting/observability source with Blink's native Tables feature for maintaining the corporate IP/CIDR reference data — a lightweight, self-contained integration footprint with room to expand to additional security tools.
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 1 use cases | 5 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| Security alerts auto-triaged and closed for known corporate IP ranges | 5 | Alert IP Triage - Known Ranges Auto-Close |
Use Case Summary
| Use Case | Category | Playbooks |
|---|---|---|
| Alert IP Triage & Auto-Close | SOC | 1 |
Use Cases
1. Alert IP Triage & Auto-Close
Category: SOC
Subcategories: Agentic SOC, Alert enrichment / IOC lookup
Description:
Automatically extracts IP addresses from incoming Coralogix alerts, checks them against a maintained table of known corporate IP/CIDR ranges, and auto-closes the alert when every IP resolves to trusted internal infrastructure.
Business problem solved:
Cuts manual triage effort by filtering out and closing alerts that only reference recognized, trusted internal IP ranges — freeing analyst attention for alerts involving unrecognized or external IPs.
Integrations: Coralogix · Blink Tables
Playbooks
| Playbook | Executions | Role |
|---|---|---|
| Alert IP Triage - Known Ranges Auto-Close | 5 | Extracts alert IPs, checks them against corporate CIDR ranges, and auto-closes the alert if all IPs are known internal infrastructure. |
Key Observations
- Strengths: The deployed playbook automates a real first-pass triage decision (auto-close on fully-known IP ranges), directly reducing analyst noise for Coralogix-sourced alerts.
- Gaps: Sandbox SRC currently has a single automated use case with low execution volume (5 runs/12 months), indicating an early-stage deployment. There is no coverage yet for other SOC subcategories (case management, EDR containment, phishing response, identity threat response) or other pillars (Cloud Security, Vulnerability Mgmt, GRC, IAM).
- Integration ecosystem: The workflow pairs Coralogix as the alerting/observability source with Blink's native Tables feature for maintaining the corporate IP/CIDR reference data — a lightweight, self-contained integration footprint with room to expand to additional security tools.
E New Integrations (detail) 1 added in last 30d
New Integrations Added - Last 30 Days
| Tenant | Integration | Connection Name | Added |
|---|---|---|---|
| Sandbox SRC | coralogix-incident-management | my_coralogix_incident_management_connection | 2026-08-23 |