01Business KPIs — Last 12 Months
02Use Cases & Playbook Distribution
Cumulative Playbooks Built — Last 90 Days
New Active Workflows Added — Last 30 Days
| Use Case | Key Business KPIs | Share of Activity | Playbooks |
|---|---|---|---|
| OT Alert Triage & Lifecycle Management | 3,090 executions | 2.3% | 9 9 active |
| OT Asset Inventory & Security Metrics | 1,303 executions | 1.0% | 24 24 active |
| SIEM Alert Monitoring & SOC Escalation |
| 64.6% | 6 6 active |
| ITSM Case & Incident Automation |
| 0.2% | 8 8 active |
| Operational Notification Infrastructure | 43,388 executions | 31.8% | 8 7 active |
| Total | 136,166 executions | 100% | 55 54 active |
Use Case Growth Over Time
03Integration Ecosystem
04Key Observations
Strengths
Specialized OT security automation is the core differentiator. The dominant workload is OT/ICS-specific — Claroty CTD and XDome cover the industrial security layer while Sumo Logic serves as the SIEM aggregation point. This is a rare, mature automation pattern that directly addresses Rockwell's industrial cybersecurity mandate. The pipeline from OT sensor → Blink → SIEM → ITSM is fully wired.
Multi-workspace SOC hierarchy demonstrates operational maturity. Playbooks run across three distinct workspaces — one primary (bb1daa88) and two SOC-Parent environments (16512276, b780643a) — indicating a deliberate multi-site or multi-team operational design. The SOC-Parent workspaces together account for the majority of active executions, suggesting these are the live production environments.
Sumo Logic oversight automation runs continuously at scale. The unacknowledged insights notification cron (every 2 minutes, across 3 workspaces) logged 48,372 combined runs. This represents persistent, machine-enforced analyst accountability — every open SIEM alert has a defined follow-up cadence without manual process overhead.
Claroty CTD alert resolution is highly active. SubFlow Claroty CTD Resolve Alert recorded 1,343 combined executions (326 in workspace 16512276, 1,017 in b780643a) — the highest volume of any direct operational action, reflecting automated OT alert closure as the primary SOC activity.
###
Gaps & Risks
Sumo Logic error rate in primary workspace warrants investigation. SubFlow - Send Error Message Via Teams SumoLogic executed 15,073 times in workspace bb1daa88 — a near 1:1 ratio with the Sumo Logic Unacknowledged Insights notification scheduler in the same workspace (15,075). This strongly suggests the workflow was failing on nearly every run for an extended period. The SOC-Parent workspaces show much lower error rates (6 and 15 respectively), suggesting those environments operate more cleanly.
Oracle integration is built but has zero production executions. The full Oracle ticket automation (Sumo Logic Create Oracle Ticket + Oracle Get Incident and Close) across all three workspaces shows 0 executions. This path appears to be a configured but untriggered integration — either the trigger condition is never met or the integration was superseded by the SNOW workflow.
SIEM enrichment automation is significantly underutilized. Sumo Logic SIEM Enrichment Automation recorded only 8 total executions across active workspaces despite being a webhook-triggered event automation. This likely means the Sumo Logic enrichment webhook is either not configured to fire broadly, or insights are reaching closure without triggering the enrichment path — a potential coverage gap in alert context.
XDome automation is nascent. XDome Get Devices (1 execution), XDome Get Devices Related to Alerts (1 execution), and XDome Execution Scheduler (1 execution) show near-zero activity. XDome alert closure subflows have 0 executions across all workspaces. The integration exists but has not been operationalized at scale — representing an opportunity to extend coverage to the IoT/OT device layer.
Several "5.0" variant playbooks overlap with existing production flows. A set of "5.0"-suffixed playbooks (Claroty_CTD_Execute_Site_Metrics_Assets 5.0, Claroty CTD - Get Alert Count 5.0, etc.) coexist with their non-5.0 counterparts. Both versions appear active in some workspaces. Without clear versioning governance, this risks duplicate data collection, inconsistent behavior across sites, and compounding maintenance overhead.
Integration Ecosystem
| Integration | Role |
|---|---|
| Claroty CTD | OT/ICS alert source, asset inventory, unsecured protocol detection, site metrics |
| XDome | IoT/OT device inventory and alert-correlated device data |
| Sumo Logic | Central SIEM — receives OT data, generates insights, drives alert closure and ticket creation |
| ServiceNow | ITSM — receives security cases and health incidents from OT/SIEM events |
| Oracle | Secondary ITSM — ticket creation and bidirectional closure (built, not yet active) |
| Microsoft Teams | SOC analyst notification channel for unacknowledged alerts and error escalation |
A Case Management
Case Management
No case management data found for this customer.
B AI Agents
AI Agents
No agent data found for this customer.
C Self-Service & Webforms
Self-Service Applications
No self-service usage data found for this customer.
Webforms
No webform usage data found for this customer.
D Full Use Case Analysis 5 use cases | 136,412 executions (12m)
Business KPIs
| Metric | Count | Playbook |
|---|---|---|
| SIEM alert oversight sweeps completed (unacknowledged insight monitoring) | 48,372 | Sumo Logic Unacknowledged Insights Teams Notification (all workspaces combined) |
| OT alert batches auto-archived from Claroty CTD | 93 | Claroty CTD Archive Old Alerts v2 (all workspaces combined) |
| ITSM health incidents automatically filed | 106 | Create SNOW Health Incident (SOC-Parent) |
| ITSM security cases automatically created | 11 | Create SNOW Security Case (SOC-Parent) |
| Sumo Logic insights automatically closed | 11 | Sumo Logic — Insight Closure (SOC-Parent) |
| OT site firmware/version audits completed | 6 | Claroty CTD Get Site Version Workflow (all workspaces) |
| OT sites audited for unsecured protocol baseline deviations | 3 | Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol (all workspaces) |
| Sumo Logic SIEM insights enriched via automation | 8 | Sumo Logic SIEM Enrichment Automation (SOC-Parent) |
Use Case Summary
| Use Case | Playbook Count | Category | Subcategories |
|---|---|---|---|
| OT Alert Triage & Lifecycle Management | 13 | SOC | Case mgmt & SOAR, Alert enrichment / IOC lookup |
| OT Asset Inventory & Security Metrics | 32 | Other | IT/OT & network infra monitoring |
| SIEM Alert Monitoring & SOC Escalation | 9 | SOC | SIEM & log pipeline monitoring, Agentic SOC |
| ITSM Case & Incident Automation | 12 | SOC | Case mgmt & SOAR |
| Operational Notification Infrastructure | 10 | Other | SaaS / IT administration |
| Total | 76 |
Use Cases
1. OT Alert Triage & Lifecycle Management
Category: SOC
Subcategories: Case mgmt & SOAR, Alert enrichment / IOC lookup
Description: Automated lifecycle management of OT/ICS security alerts generated by Claroty CTD across distributed industrial sites — including scheduled batch archival of aged alerts, per-run resolution of acknowledged findings, bidirectional closure linked to Sumo Logic insight status, and monthly alert count reporting per site. Designed to operate across three parallel Blink workspaces serving different site groups.
Business Problem: Claroty CTD generates continuous, high-volume alert streams across OT environments. Without automation, SOC analysts must manually review, archive, and close alerts that are aged, duplicated, or already remediated — creating backlogs that mask genuine threats and slow mean-time-to-resolve.
Integrations: Claroty CTD, Sumo Logic (for insight-correlated closures), Microsoft Teams (error escalation)
| Playbook | Workspace | Automation Type | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|---|
| Claroty CTD Archive Old Alerts v2 | bb1daa88 | Scheduled (daily, 22:00 ET) | 47 | SOC | Case mgmt & SOAR |
| Claroty CTD Archive Old Alerts v2 (SOC-Parent) | 16512276 | Scheduled (daily, 22:00 ET) | 23 | SOC | Case mgmt & SOAR |
| Claroty CTD Archive Old Alerts v2 (SOC-Parent) | b780643a | Scheduled (daily, 22:00 ET) | 23 | SOC | Case mgmt & SOAR |
| SubFlow Claroty CTD Resolve Alert | bb1daa88 | On-demand | 0 | SOC | Case mgmt & SOAR |
| SubFlow Claroty CTD Resolve Alert (SOC-Parent) | 16512276 | On-demand | 326 | SOC | Case mgmt & SOAR |
| SubFlow Claroty CTD Resolve Alert (SOC-Parent) | b780643a | On-demand | 1,017 | SOC | Case mgmt & SOAR |
| Subflow - Claroty - Close Alert Related To Sumo Insight | bb1daa88 | On-demand | 0 | SOC | Alert enrichment / IOC lookup |
| Subflow - Claroty - Close Alert Related To Sumo Insight (SOC-Parent) | 16512276 | On-demand | 3 | SOC | Alert enrichment / IOC lookup |
| Subflow - Claroty - Close Alert Related To Sumo Insight (SOC-Parent) | b780643a | On-demand | 26 | SOC | Alert enrichment / IOC lookup |
| Claroty CTD - Get Alert Count (SOC-Parent) | 16512276 | Scheduled (monthly) | 2 | SOC | Case mgmt & SOAR |
| Claroty CTD - Get Alert Count (SOC-Parent) | b780643a | Scheduled (monthly) | 2 | SOC | Case mgmt & SOAR |
| Claroty CTD - Get Alert Count 5.0 | bb1daa88 | Scheduled (monthly) | 1 | SOC | Case mgmt & SOAR |
| Claroty CTD - Get Alert Count 5.0 (SOC-Parent) | 16512276 | Scheduled (monthly) | 1 | SOC | Case mgmt & SOAR |
2. OT Asset Inventory & Security Metrics
Category: Other
Subcategories: IT/OT & network infra monitoring
Description: Automated collection and forwarding of OT asset data from Claroty CTD and XDome to Sumo Logic — covering assets with active security insights, devices operating on unsecured protocols against baseline, per-site firmware versions, and IoT/OT device records related to active alerts. Runs on monthly schedules and event triggers, pushing structured data to the SIEM for centralized analysis and reporting.
Business Problem: Maintaining an accurate, up-to-date OT asset inventory across geographically distributed industrial sites requires pulling from multiple security tools. Without automation, asset data becomes stale between collection cycles, unsecured protocol deviations go unreported, and site firmware posture is unknown — creating persistent blind spots in the organization's OT security picture.
Integrations: Claroty CTD, XDome, Sumo Logic, Microsoft Teams
| Playbook | Workspace | Automation Type | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|---|
| Claroty_CTD_Get_Assets_With_Insights Reworked | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Get_Assets_With_Insights Reworked (SOC-Parent) | 16512276 | On-demand | 2 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Get_Assets_With_Insights Reworked (SOC-Parent) | b780643a | On-demand | 1 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Get_Assets_With_Insights Reworked 5.0 | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Get_Assets_With_Insights Reworked 5.0 (SOC-Parent) | 16512276 | On-demand | 2 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Execute_Site_Metrics_Assets (SOC-Parent) | 16512276 | Scheduled (monthly, 1st) | 1 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Execute_Site_Metrics_Assets (SOC-Parent) | b780643a | Scheduled (monthly, 1st) | 1 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Execute_Site_Metrics_Assets 5.0 | bb1daa88 | Scheduled (monthly, 1st) | 1 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Execute_Site_Metrics_Assets 5.0 (SOC-Parent) | 16512276 | Scheduled (monthly, 1st) | 1 | Other | IT/OT & network infra monitoring |
| Claroty_Get Asset Unsecured Protocol From Baseline v3 | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| Claroty_Get Asset Unsecured Protocol From Baseline v3 (SOC-Parent) | 16512276 | On-demand | 2 | Other | IT/OT & network infra monitoring |
| Claroty_Get Asset Unsecured Protocol From Baseline v3 (SOC-Parent) | b780643a | On-demand | 1 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol (SOC-Parent) | 16512276 | Scheduled (monthly, 1st) | 1 | Other | IT/OT & network infra monitoring |
| Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol (SOC-Parent) | b780643a | Scheduled (monthly, 1st) | 1 | Other | IT/OT & network infra monitoring |
| Claroty CTD Get Site Version Workflow (SOC-Parent) | 16512276 | Scheduled (weekly, Mon) | 3 | Other | IT/OT & network infra monitoring |
| Claroty CTD Get Site Version Workflow (SOC-Parent) | b780643a | Scheduled (weekly, Mon) | 3 | Other | IT/OT & network infra monitoring |
| SubFlow Send Claroty Asset Data Iteratively To Sumo | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| SubFlow Send Claroty Asset Data Iteratively To Sumo (SOC-Parent) | 16512276 | On-demand | 5 | Other | IT/OT & network infra monitoring |
| SubFlow Send Claroty Asset Data Iteratively To Sumo (SOC-Parent) | b780643a | On-demand | 598 | Other | IT/OT & network infra monitoring |
| SubFlow Send Claroty Asset Data Iteratively To Sumo 5.0 | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| SubFlow Send Claroty Asset Data Iteratively To Sumo 5.0 (SOC-Parent) | 16512276 | On-demand | 3 | Other | IT/OT & network infra monitoring |
| SubFlow - Send Claroty Data To Sumo Webhook | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| SubFlow - Send Claroty Data To Sumo Webhook (SOC-Parent) | 16512276 | On-demand | 12 | Other | IT/OT & network infra monitoring |
| SubFlow - Send Claroty Data To Sumo Webhook (SOC-Parent) | b780643a | On-demand | 7 | Other | IT/OT & network infra monitoring |
| SubFlow - Send Claroty Data To Sumo Webhook 5.0 | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| SubFlow - Send Claroty Data To Sumo Webhook 5.0 (SOC-Parent) | 16512276 | On-demand | 2 | Other | IT/OT & network infra monitoring |
| XDome Get Devices and Send to Sumo | bb1daa88 | On-demand | 1 | Other | IT/OT & network infra monitoring |
| XDome Get Devices Related to Alerts and Send to Sumo | bb1daa88 | On-demand | 1 | Other | IT/OT & network infra monitoring |
| XDome Execution Scheduler | bb1daa88 | Scheduled (monthly, 28th) | 1 | Other | IT/OT & network infra monitoring |
| Subflow - XDome - Close Alert Related To Sumo Insight | bb1daa88 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| Subflow - XDome - Close Alert Related To Sumo Insight (SOC-Parent) | 16512276 | On-demand | 0 | Other | IT/OT & network infra monitoring |
| Subflow - XDome - Close Alert Related To Sumo Insight (SOC-Parent) | b780643a | On-demand | 0 | Other | IT/OT & network infra monitoring |
3. SIEM Alert Monitoring & SOC Escalation
Category: SOC
Subcategories: SIEM & log pipeline monitoring, Agentic SOC
Description: Continuous, every-2-minute polling of Sumo Logic for unacknowledged security insights, with automated Microsoft Teams notifications pushed to SOC analysts ensuring timely acknowledgement. Complemented by event-driven SIEM enrichment (triggered on new/updated insights via Sumo Logic webhook) and automated insight closure when investigations conclude.
Business Problem: In high-volume SOC environments, unacknowledged SIEM alerts accumulate silently. Without automated follow-up, analysts have no persistent signal that open insights require action, leading to increased MTTA and potential missed detections. This automation enforces analyst accountability at machine speed.
Integrations: Sumo Logic, Microsoft Teams
| Playbook | Workspace | Automation Type | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|---|
| Sumo Logic Unacknowledged Insights Teams Notification | bb1daa88 | Scheduled (every 2 min) | 15,075 | SOC | SIEM & log pipeline monitoring |
| Sumo Logic Unacknowledged Insights Teams Notification (SOC-Parent) | 16512276 | Scheduled (every 2 min) | 16,622 | SOC | SIEM & log pipeline monitoring |
| Sumo Logic Unacknowledged Insights Teams Notification (SOC-Parent) | b780643a | Scheduled (every 2 min) | 16,675 | SOC | SIEM & log pipeline monitoring |
| Sumo Logic SIEM Enrichment Automation | bb1daa88 | Event (Sumo Logic webhook) | 0 | SOC | Alert enrichment / IOC lookup |
| Sumo Logic SIEM Enrichment Automation (SOC-Parent) | 16512276 | Event (Sumo Logic webhook) | 2 | SOC | Alert enrichment / IOC lookup |
| Sumo Logic SIEM Enrichment Automation (SOC-Parent) | b780643a | Event (Sumo Logic webhook) | 6 | SOC | Alert enrichment / IOC lookup |
| Sumo Logic - Insight Closure | bb1daa88 | Event (custom webhook) | 0 | SOC | Agentic SOC |
| Sumo Logic - Insight Closure (SOC-Parent) | 16512276 | Event (custom webhook) | 2 | SOC | Agentic SOC |
| Sumo Logic - Insight Closure (SOC-Parent) | b780643a | Event (custom webhook) | 9 | SOC | Agentic SOC |
4. ITSM Case & Incident Automation
Category: SOC
Subcategories: Case mgmt & SOAR
Description: Event-driven creation of ServiceNow security cases and health incidents triggered from Sumo Logic and OT monitoring events. Also includes bidirectional Oracle ticket management — automating ticket creation from SIEM insight escalations and closing tickets when Sumo Logic insights resolve. Ensures every security and health event generates a properly structured, audit-ready ITSM record.
Business Problem: Manual ITSM ticket creation for security events introduces delays between detection and documentation, risks inconsistent data entry, and removes traceability. Automated case creation ensures immediate, structured ticket filing without analyst overhead, supporting SLA compliance and incident audit trails.
Integrations: ServiceNow, Oracle, Sumo Logic
| Playbook | Workspace | Automation Type | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|---|
| Create SNOW Security Case | bb1daa88 | Event (custom webhook) | 0 | SOC | Case mgmt & SOAR |
| Create SNOW Security Case (SOC-Parent) | 16512276 | Event (custom webhook) | 0 | SOC | Case mgmt & SOAR |
| Create SNOW Security Case (SOC-Parent) | b780643a | Event (custom webhook) | 11 | SOC | Case mgmt & SOAR |
| Create SNOW Health Incident | bb1daa88 | Event (custom webhook) | 0 | SOC | Case mgmt & SOAR |
| Create SNOW Health Incident (SOC-Parent) | 16512276 | Event (custom webhook) | 72 | SOC | Case mgmt & SOAR |
| Create SNOW Health Incident (SOC-Parent) | b780643a | Event (custom webhook) | 34 | SOC | Case mgmt & SOAR |
| Sumo Logic Create Oracle Ticket | bb1daa88 | Event (custom webhook) | 0 | SOC | Case mgmt & SOAR |
| Sumo Logic Create Oracle Ticket (SOC-Parent) | 16512276 | Event (custom webhook) | 0 | SOC | Case mgmt & SOAR |
| Sumo Logic Create Oracle Ticket (SOC-Parent) | b780643a | Event (custom webhook) | 0 | SOC | Case mgmt & SOAR |
| Oracle Get Incident and Close | bb1daa88 | On-demand | 0 | SOC | Case mgmt & SOAR |
| Oracle Get Incident and Close (SOC-Parent) | 16512276 | On-demand | 0 | SOC | Case mgmt & SOAR |
| Oracle Get Incident and Close (SOC-Parent) | b780643a | On-demand | 0 | SOC | Case mgmt & SOAR |
5. Operational Notification Infrastructure
Category: Other
Subcategories: SaaS / IT administration
Description: Cross-cutting utility playbooks that provide error escalation via Microsoft Teams for every automation domain above — Claroty CTD operations, Sumo Logic flows, and XDome workflows each have a dedicated Teams error subflow. Executions of these playbooks reflect error handling overhead rather than primary business outcomes. Also includes a one-time Getting Started test workflow.
Note: The SubFlow - Send Error Message Via Teams SumoLogic recorded 15,073 executions in the bb1daa88 workspace — nearly matching the execution volume of the Sumo Logic Unacknowledged Insights notification scheduler (15,075). This 1:1 ratio suggests the primary Sumo Logic workflow was consistently encountering an error condition on almost every run during part of the year, warranting investigation.
| Playbook | Workspace | Automation Type | Executions (12 mo) | Category | Subcategory |
|---|---|---|---|---|---|
| Getting Started - Hello World | 163d05d1 | On-demand | 1 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams | bb1daa88 | On-demand | 47 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams SumoLogic | bb1daa88 | On-demand | 15,073 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams XDome | bb1daa88 | On-demand | 2 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams (SOC-Parent) | 16512276 | On-demand | 4 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams SumoLogic (SOC-Parent) | 16512276 | On-demand | 6 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams (SOC-Parent) | b780643a | On-demand | 1 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams SumoLogic (SOC-Parent) | b780643a | On-demand | 15 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams 5.0 | bb1daa88 | On-demand | 1 | Other | SaaS / IT administration |
| SubFlow - Send Error Message Via Teams 5.0 (SOC-Parent) | 16512276 | On-demand | 0 | Other | SaaS / IT administration |
Key Observations
Strengths
Specialized OT security automation is the core differentiator. The dominant workload is OT/ICS-specific — Claroty CTD and XDome cover the industrial security layer while Sumo Logic serves as the SIEM aggregation point. This is a rare, mature automation pattern that directly addresses Rockwell's industrial cybersecurity mandate. The pipeline from OT sensor → Blink → SIEM → ITSM is fully wired.
Multi-workspace SOC hierarchy demonstrates operational maturity. Playbooks run across three distinct workspaces — one primary (bb1daa88) and two SOC-Parent environments (16512276, b780643a) — indicating a deliberate multi-site or multi-team operational design. The SOC-Parent workspaces together account for the majority of active executions, suggesting these are the live production environments.
Sumo Logic oversight automation runs continuously at scale. The unacknowledged insights notification cron (every 2 minutes, across 3 workspaces) logged 48,372 combined runs. This represents persistent, machine-enforced analyst accountability — every open SIEM alert has a defined follow-up cadence without manual process overhead.
Claroty CTD alert resolution is highly active. SubFlow Claroty CTD Resolve Alert recorded 1,343 combined executions (326 in workspace 16512276, 1,017 in b780643a) — the highest volume of any direct operational action, reflecting automated OT alert closure as the primary SOC activity.
Gaps & Risks
Sumo Logic error rate in primary workspace warrants investigation. SubFlow - Send Error Message Via Teams SumoLogic executed 15,073 times in workspace bb1daa88 — a near 1:1 ratio with the Sumo Logic Unacknowledged Insights notification scheduler in the same workspace (15,075). This strongly suggests the workflow was failing on nearly every run for an extended period. The SOC-Parent workspaces show much lower error rates (6 and 15 respectively), suggesting those environments operate more cleanly.
Oracle integration is built but has zero production executions. The full Oracle ticket automation (Sumo Logic Create Oracle Ticket + Oracle Get Incident and Close) across all three workspaces shows 0 executions. This path appears to be a configured but untriggered integration — either the trigger condition is never met or the integration was superseded by the SNOW workflow.
SIEM enrichment automation is significantly underutilized. Sumo Logic SIEM Enrichment Automation recorded only 8 total executions across active workspaces despite being a webhook-triggered event automation. This likely means the Sumo Logic enrichment webhook is either not configured to fire broadly, or insights are reaching closure without triggering the enrichment path — a potential coverage gap in alert context.
XDome automation is nascent. XDome Get Devices (1 execution), XDome Get Devices Related to Alerts (1 execution), and XDome Execution Scheduler (1 execution) show near-zero activity. XDome alert closure subflows have 0 executions across all workspaces. The integration exists but has not been operationalized at scale — representing an opportunity to extend coverage to the IoT/OT device layer.
Several "5.0" variant playbooks overlap with existing production flows. A set of "5.0"-suffixed playbooks (Claroty_CTD_Execute_Site_Metrics_Assets 5.0, Claroty CTD - Get Alert Count 5.0, etc.) coexist with their non-5.0 counterparts. Both versions appear active in some workspaces. Without clear versioning governance, this risks duplicate data collection, inconsistent behavior across sites, and compounding maintenance overhead.
Integration Ecosystem
| Integration | Role |
|---|---|
| Claroty CTD | OT/ICS alert source, asset inventory, unsecured protocol detection, site metrics |
| XDome | IoT/OT device inventory and alert-correlated device data |
| Sumo Logic | Central SIEM — receives OT data, generates insights, drives alert closure and ticket creation |
| ServiceNow | ITSM — receives security cases and health incidents from OT/SIEM events |
| Oracle | Secondary ITSM — ticket creation and bidirectional closure (built, not yet active) |
| Microsoft Teams | SOC analyst notification channel for unacknowledged alerts and error escalation |
E New Integrations (detail) 0 added in last 30d
New Integrations Added - Last 30 Days
No new integrations found, or DB query was skipped.