Blink Security Automation — Confidential

rockwell_c-i-production-eu — Customer Success Report

Generated 2026-08-30 | rockwell_c-i-production-eu-value-report.md
2026-08-30Report Date
86Total Playbooks
53Unique Workflows (12m)
471,460Actions Automated (12m)
$121,260Money Saved (12m)
Last 12 MonthsData Period
CSM — Please review before sharing. AI-generated content may contain errors. Verify key metrics before sending to the customer.

01Business KPIs — Last 12 Months

86
Total playbooks built
all non-deleted workflows
76
Active playbooks
currently enabled
53
Unique workflows executed (12m)
distinct workflows that ran
471,460
Actions automated (12m)
completed action steps
2,619.2h
Hours saved (12m)
@ 20s per action
$121,260
Money saved (12m)
@ $100K avg salary
0
New active workflows (last 30d)
recently created & enabled
0
Total cases managed
0 opened in last 12m
N/A
MTTR — mean time to resolve
closed cases, last 12m
In the last 12 months, Blink automated: - 48,372 SIEM alert oversight checks completed — ensuring every open Sumo Logic insight received analyst follow-through - 117 ITSM incidents and security cases automatically filed in ServiceNow without manual ticket creation - 93 OT alert batches archived from Claroty CTD, keeping the SOC alert queue clean across distributed industrial sites - 11 Sumo Logic security insights automatically closed upon resolution - 8 SIEM insights enriched with contextual data from OT sources at time of detection

02Use Cases & Playbook Distribution

Cumulative Playbooks Built — Last 90 Days

New Active Workflows Added — Last 30 Days

Use Case Summary
Use CaseKey Business KPIsShare of ActivityPlaybooks
OT Alert Triage & Lifecycle Management3,090 executions
2.3%
9
9 active
OT Asset Inventory & Security Metrics1,303 executions
1.0%
24
24 active
SIEM Alert Monitoring & SOC Escalation
  • 8Sumo Logic SIEM insights enriched via automation
64.6%
6
6 active
ITSM Case & Incident Automation
  • 106ITSM health incidents automatically filed
  • 11ITSM security cases automatically created
0.2%
8
8 active
Operational Notification Infrastructure43,388 executions
31.8%
8
7 active
Total136,166 executions100%
55
54 active

Use Case Growth Over Time

59 unique playbooks  |  5 operational use cases  |  136,412 total executions (12m)  |  2026-04 to 2026-07
Toggle:
Toggle:

03Integration Ecosystem

OT Alert Triage & Lifecycle Management
Sumo Logic Claroty CTD
OT Asset Inventory & Security Metrics
Claroty CTD Claroty xDome
Operational Notification Infrastructure
Microsoft Teams
ITSM Case & Incident Automation
Sumo Logic ServiceNow Oracle Service Cloud
SIEM Alert Monitoring & SOC Escalation
Sumo Logic Claroty CTD Claroty xDome

04Key Observations

✓  Strengths

Strengths

Specialized OT security automation is the core differentiator. The dominant workload is OT/ICS-specific — Claroty CTD and XDome cover the industrial security layer while Sumo Logic serves as the SIEM aggregation point. This is a rare, mature automation pattern that directly addresses Rockwell's industrial cybersecurity mandate. The pipeline from OT sensor → Blink → SIEM → ITSM is fully wired.

Multi-workspace SOC hierarchy demonstrates operational maturity. Playbooks run across three distinct workspaces — one primary (bb1daa88) and two SOC-Parent environments (16512276, b780643a) — indicating a deliberate multi-site or multi-team operational design. The SOC-Parent workspaces together account for the majority of active executions, suggesting these are the live production environments.

Sumo Logic oversight automation runs continuously at scale. The unacknowledged insights notification cron (every 2 minutes, across 3 workspaces) logged 48,372 combined runs. This represents persistent, machine-enforced analyst accountability — every open SIEM alert has a defined follow-up cadence without manual process overhead.

Claroty CTD alert resolution is highly active. SubFlow Claroty CTD Resolve Alert recorded 1,343 combined executions (326 in workspace 16512276, 1,017 in b780643a) — the highest volume of any direct operational action, reflecting automated OT alert closure as the primary SOC activity.

###

△  Gaps & Growth Opportunities

Gaps & Risks

Sumo Logic error rate in primary workspace warrants investigation. SubFlow - Send Error Message Via Teams SumoLogic executed 15,073 times in workspace bb1daa88 — a near 1:1 ratio with the Sumo Logic Unacknowledged Insights notification scheduler in the same workspace (15,075). This strongly suggests the workflow was failing on nearly every run for an extended period. The SOC-Parent workspaces show much lower error rates (6 and 15 respectively), suggesting those environments operate more cleanly.

Oracle integration is built but has zero production executions. The full Oracle ticket automation (Sumo Logic Create Oracle Ticket + Oracle Get Incident and Close) across all three workspaces shows 0 executions. This path appears to be a configured but untriggered integration — either the trigger condition is never met or the integration was superseded by the SNOW workflow.

SIEM enrichment automation is significantly underutilized. Sumo Logic SIEM Enrichment Automation recorded only 8 total executions across active workspaces despite being a webhook-triggered event automation. This likely means the Sumo Logic enrichment webhook is either not configured to fire broadly, or insights are reaching closure without triggering the enrichment path — a potential coverage gap in alert context.

XDome automation is nascent. XDome Get Devices (1 execution), XDome Get Devices Related to Alerts (1 execution), and XDome Execution Scheduler (1 execution) show near-zero activity. XDome alert closure subflows have 0 executions across all workspaces. The integration exists but has not been operationalized at scale — representing an opportunity to extend coverage to the IoT/OT device layer.

Several "5.0" variant playbooks overlap with existing production flows. A set of "5.0"-suffixed playbooks (Claroty_CTD_Execute_Site_Metrics_Assets 5.0, Claroty CTD - Get Alert Count 5.0, etc.) coexist with their non-5.0 counterparts. Both versions appear active in some workspaces. Without clear versioning governance, this risks duplicate data collection, inconsistent behavior across sites, and compounding maintenance overhead.

Integration Ecosystem

Integration Role
Claroty CTD OT/ICS alert source, asset inventory, unsecured protocol detection, site metrics
XDome IoT/OT device inventory and alert-correlated device data
Sumo Logic Central SIEM — receives OT data, generates insights, drives alert closure and ticket creation
ServiceNow ITSM — receives security cases and health incidents from OT/SIEM events
Oracle Secondary ITSM — ticket creation and bidirectional closure (built, not yet active)
Microsoft Teams SOC analyst notification channel for unacknowledged alerts and error escalation
Appendices
A Case Management

Case Management

No case management data found for this customer.

B AI Agents

AI Agents

No agent data found for this customer.

C Self-Service & Webforms

Self-Service Applications

No self-service usage data found for this customer.

Webforms

No webform usage data found for this customer.

D Full Use Case Analysis 5 use cases | 136,412 executions (12m)

Business KPIs

Metric Count Playbook
SIEM alert oversight sweeps completed (unacknowledged insight monitoring) 48,372 Sumo Logic Unacknowledged Insights Teams Notification (all workspaces combined)
OT alert batches auto-archived from Claroty CTD 93 Claroty CTD Archive Old Alerts v2 (all workspaces combined)
ITSM health incidents automatically filed 106 Create SNOW Health Incident (SOC-Parent)
ITSM security cases automatically created 11 Create SNOW Security Case (SOC-Parent)
Sumo Logic insights automatically closed 11 Sumo Logic — Insight Closure (SOC-Parent)
OT site firmware/version audits completed 6 Claroty CTD Get Site Version Workflow (all workspaces)
OT sites audited for unsecured protocol baseline deviations 3 Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol (all workspaces)
Sumo Logic SIEM insights enriched via automation 8 Sumo Logic SIEM Enrichment Automation (SOC-Parent)
In the last 12 months, Blink automated: - 48,372 SIEM alert oversight checks completed — ensuring every open Sumo Logic insight received analyst follow-through - 117 ITSM incidents and security cases automatically filed in ServiceNow without manual ticket creation - 93 OT alert batches archived from Claroty CTD, keeping the SOC alert queue clean across distributed industrial sites - 11 Sumo Logic security insights automatically closed upon resolution - 8 SIEM insights enriched with contextual data from OT sources at time of detection

Use Case Summary

Use Case Playbook Count Category Subcategories
OT Alert Triage & Lifecycle Management 13 SOC Case mgmt & SOAR, Alert enrichment / IOC lookup
OT Asset Inventory & Security Metrics 32 Other IT/OT & network infra monitoring
SIEM Alert Monitoring & SOC Escalation 9 SOC SIEM & log pipeline monitoring, Agentic SOC
ITSM Case & Incident Automation 12 SOC Case mgmt & SOAR
Operational Notification Infrastructure 10 Other SaaS / IT administration
Total 76

Use Cases

1. OT Alert Triage & Lifecycle Management

Category: SOC

Subcategories: Case mgmt & SOAR, Alert enrichment / IOC lookup

Description: Automated lifecycle management of OT/ICS security alerts generated by Claroty CTD across distributed industrial sites — including scheduled batch archival of aged alerts, per-run resolution of acknowledged findings, bidirectional closure linked to Sumo Logic insight status, and monthly alert count reporting per site. Designed to operate across three parallel Blink workspaces serving different site groups.

Business Problem: Claroty CTD generates continuous, high-volume alert streams across OT environments. Without automation, SOC analysts must manually review, archive, and close alerts that are aged, duplicated, or already remediated — creating backlogs that mask genuine threats and slow mean-time-to-resolve.

Integrations: Claroty CTD, Sumo Logic (for insight-correlated closures), Microsoft Teams (error escalation)

Playbook Workspace Automation Type Executions (12 mo) Category Subcategory
Claroty CTD Archive Old Alerts v2 bb1daa88 Scheduled (daily, 22:00 ET) 47 SOC Case mgmt & SOAR
Claroty CTD Archive Old Alerts v2 (SOC-Parent) 16512276 Scheduled (daily, 22:00 ET) 23 SOC Case mgmt & SOAR
Claroty CTD Archive Old Alerts v2 (SOC-Parent) b780643a Scheduled (daily, 22:00 ET) 23 SOC Case mgmt & SOAR
SubFlow Claroty CTD Resolve Alert bb1daa88 On-demand 0 SOC Case mgmt & SOAR
SubFlow Claroty CTD Resolve Alert (SOC-Parent) 16512276 On-demand 326 SOC Case mgmt & SOAR
SubFlow Claroty CTD Resolve Alert (SOC-Parent) b780643a On-demand 1,017 SOC Case mgmt & SOAR
Subflow - Claroty - Close Alert Related To Sumo Insight bb1daa88 On-demand 0 SOC Alert enrichment / IOC lookup
Subflow - Claroty - Close Alert Related To Sumo Insight (SOC-Parent) 16512276 On-demand 3 SOC Alert enrichment / IOC lookup
Subflow - Claroty - Close Alert Related To Sumo Insight (SOC-Parent) b780643a On-demand 26 SOC Alert enrichment / IOC lookup
Claroty CTD - Get Alert Count (SOC-Parent) 16512276 Scheduled (monthly) 2 SOC Case mgmt & SOAR
Claroty CTD - Get Alert Count (SOC-Parent) b780643a Scheduled (monthly) 2 SOC Case mgmt & SOAR
Claroty CTD - Get Alert Count 5.0 bb1daa88 Scheduled (monthly) 1 SOC Case mgmt & SOAR
Claroty CTD - Get Alert Count 5.0 (SOC-Parent) 16512276 Scheduled (monthly) 1 SOC Case mgmt & SOAR

2. OT Asset Inventory & Security Metrics

Category: Other

Subcategories: IT/OT & network infra monitoring

Description: Automated collection and forwarding of OT asset data from Claroty CTD and XDome to Sumo Logic — covering assets with active security insights, devices operating on unsecured protocols against baseline, per-site firmware versions, and IoT/OT device records related to active alerts. Runs on monthly schedules and event triggers, pushing structured data to the SIEM for centralized analysis and reporting.

Business Problem: Maintaining an accurate, up-to-date OT asset inventory across geographically distributed industrial sites requires pulling from multiple security tools. Without automation, asset data becomes stale between collection cycles, unsecured protocol deviations go unreported, and site firmware posture is unknown — creating persistent blind spots in the organization's OT security picture.

Integrations: Claroty CTD, XDome, Sumo Logic, Microsoft Teams

Playbook Workspace Automation Type Executions (12 mo) Category Subcategory
Claroty_CTD_Get_Assets_With_Insights Reworked bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
Claroty_CTD_Get_Assets_With_Insights Reworked (SOC-Parent) 16512276 On-demand 2 Other IT/OT & network infra monitoring
Claroty_CTD_Get_Assets_With_Insights Reworked (SOC-Parent) b780643a On-demand 1 Other IT/OT & network infra monitoring
Claroty_CTD_Get_Assets_With_Insights Reworked 5.0 bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
Claroty_CTD_Get_Assets_With_Insights Reworked 5.0 (SOC-Parent) 16512276 On-demand 2 Other IT/OT & network infra monitoring
Claroty_CTD_Execute_Site_Metrics_Assets (SOC-Parent) 16512276 Scheduled (monthly, 1st) 1 Other IT/OT & network infra monitoring
Claroty_CTD_Execute_Site_Metrics_Assets (SOC-Parent) b780643a Scheduled (monthly, 1st) 1 Other IT/OT & network infra monitoring
Claroty_CTD_Execute_Site_Metrics_Assets 5.0 bb1daa88 Scheduled (monthly, 1st) 1 Other IT/OT & network infra monitoring
Claroty_CTD_Execute_Site_Metrics_Assets 5.0 (SOC-Parent) 16512276 Scheduled (monthly, 1st) 1 Other IT/OT & network infra monitoring
Claroty_Get Asset Unsecured Protocol From Baseline v3 bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
Claroty_Get Asset Unsecured Protocol From Baseline v3 (SOC-Parent) 16512276 On-demand 2 Other IT/OT & network infra monitoring
Claroty_Get Asset Unsecured Protocol From Baseline v3 (SOC-Parent) b780643a On-demand 1 Other IT/OT & network infra monitoring
Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol (SOC-Parent) 16512276 Scheduled (monthly, 1st) 1 Other IT/OT & network infra monitoring
Claroty_CTD_Execute_Site_Metrics_UnsecuredProtocol (SOC-Parent) b780643a Scheduled (monthly, 1st) 1 Other IT/OT & network infra monitoring
Claroty CTD Get Site Version Workflow (SOC-Parent) 16512276 Scheduled (weekly, Mon) 3 Other IT/OT & network infra monitoring
Claroty CTD Get Site Version Workflow (SOC-Parent) b780643a Scheduled (weekly, Mon) 3 Other IT/OT & network infra monitoring
SubFlow Send Claroty Asset Data Iteratively To Sumo bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
SubFlow Send Claroty Asset Data Iteratively To Sumo (SOC-Parent) 16512276 On-demand 5 Other IT/OT & network infra monitoring
SubFlow Send Claroty Asset Data Iteratively To Sumo (SOC-Parent) b780643a On-demand 598 Other IT/OT & network infra monitoring
SubFlow Send Claroty Asset Data Iteratively To Sumo 5.0 bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
SubFlow Send Claroty Asset Data Iteratively To Sumo 5.0 (SOC-Parent) 16512276 On-demand 3 Other IT/OT & network infra monitoring
SubFlow - Send Claroty Data To Sumo Webhook bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
SubFlow - Send Claroty Data To Sumo Webhook (SOC-Parent) 16512276 On-demand 12 Other IT/OT & network infra monitoring
SubFlow - Send Claroty Data To Sumo Webhook (SOC-Parent) b780643a On-demand 7 Other IT/OT & network infra monitoring
SubFlow - Send Claroty Data To Sumo Webhook 5.0 bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
SubFlow - Send Claroty Data To Sumo Webhook 5.0 (SOC-Parent) 16512276 On-demand 2 Other IT/OT & network infra monitoring
XDome Get Devices and Send to Sumo bb1daa88 On-demand 1 Other IT/OT & network infra monitoring
XDome Get Devices Related to Alerts and Send to Sumo bb1daa88 On-demand 1 Other IT/OT & network infra monitoring
XDome Execution Scheduler bb1daa88 Scheduled (monthly, 28th) 1 Other IT/OT & network infra monitoring
Subflow - XDome - Close Alert Related To Sumo Insight bb1daa88 On-demand 0 Other IT/OT & network infra monitoring
Subflow - XDome - Close Alert Related To Sumo Insight (SOC-Parent) 16512276 On-demand 0 Other IT/OT & network infra monitoring
Subflow - XDome - Close Alert Related To Sumo Insight (SOC-Parent) b780643a On-demand 0 Other IT/OT & network infra monitoring

3. SIEM Alert Monitoring & SOC Escalation

Category: SOC

Subcategories: SIEM & log pipeline monitoring, Agentic SOC

Description: Continuous, every-2-minute polling of Sumo Logic for unacknowledged security insights, with automated Microsoft Teams notifications pushed to SOC analysts ensuring timely acknowledgement. Complemented by event-driven SIEM enrichment (triggered on new/updated insights via Sumo Logic webhook) and automated insight closure when investigations conclude.

Business Problem: In high-volume SOC environments, unacknowledged SIEM alerts accumulate silently. Without automated follow-up, analysts have no persistent signal that open insights require action, leading to increased MTTA and potential missed detections. This automation enforces analyst accountability at machine speed.

Integrations: Sumo Logic, Microsoft Teams

Playbook Workspace Automation Type Executions (12 mo) Category Subcategory
Sumo Logic Unacknowledged Insights Teams Notification bb1daa88 Scheduled (every 2 min) 15,075 SOC SIEM & log pipeline monitoring
Sumo Logic Unacknowledged Insights Teams Notification (SOC-Parent) 16512276 Scheduled (every 2 min) 16,622 SOC SIEM & log pipeline monitoring
Sumo Logic Unacknowledged Insights Teams Notification (SOC-Parent) b780643a Scheduled (every 2 min) 16,675 SOC SIEM & log pipeline monitoring
Sumo Logic SIEM Enrichment Automation bb1daa88 Event (Sumo Logic webhook) 0 SOC Alert enrichment / IOC lookup
Sumo Logic SIEM Enrichment Automation (SOC-Parent) 16512276 Event (Sumo Logic webhook) 2 SOC Alert enrichment / IOC lookup
Sumo Logic SIEM Enrichment Automation (SOC-Parent) b780643a Event (Sumo Logic webhook) 6 SOC Alert enrichment / IOC lookup
Sumo Logic - Insight Closure bb1daa88 Event (custom webhook) 0 SOC Agentic SOC
Sumo Logic - Insight Closure (SOC-Parent) 16512276 Event (custom webhook) 2 SOC Agentic SOC
Sumo Logic - Insight Closure (SOC-Parent) b780643a Event (custom webhook) 9 SOC Agentic SOC

4. ITSM Case & Incident Automation

Category: SOC

Subcategories: Case mgmt & SOAR

Description: Event-driven creation of ServiceNow security cases and health incidents triggered from Sumo Logic and OT monitoring events. Also includes bidirectional Oracle ticket management — automating ticket creation from SIEM insight escalations and closing tickets when Sumo Logic insights resolve. Ensures every security and health event generates a properly structured, audit-ready ITSM record.

Business Problem: Manual ITSM ticket creation for security events introduces delays between detection and documentation, risks inconsistent data entry, and removes traceability. Automated case creation ensures immediate, structured ticket filing without analyst overhead, supporting SLA compliance and incident audit trails.

Integrations: ServiceNow, Oracle, Sumo Logic

Playbook Workspace Automation Type Executions (12 mo) Category Subcategory
Create SNOW Security Case bb1daa88 Event (custom webhook) 0 SOC Case mgmt & SOAR
Create SNOW Security Case (SOC-Parent) 16512276 Event (custom webhook) 0 SOC Case mgmt & SOAR
Create SNOW Security Case (SOC-Parent) b780643a Event (custom webhook) 11 SOC Case mgmt & SOAR
Create SNOW Health Incident bb1daa88 Event (custom webhook) 0 SOC Case mgmt & SOAR
Create SNOW Health Incident (SOC-Parent) 16512276 Event (custom webhook) 72 SOC Case mgmt & SOAR
Create SNOW Health Incident (SOC-Parent) b780643a Event (custom webhook) 34 SOC Case mgmt & SOAR
Sumo Logic Create Oracle Ticket bb1daa88 Event (custom webhook) 0 SOC Case mgmt & SOAR
Sumo Logic Create Oracle Ticket (SOC-Parent) 16512276 Event (custom webhook) 0 SOC Case mgmt & SOAR
Sumo Logic Create Oracle Ticket (SOC-Parent) b780643a Event (custom webhook) 0 SOC Case mgmt & SOAR
Oracle Get Incident and Close bb1daa88 On-demand 0 SOC Case mgmt & SOAR
Oracle Get Incident and Close (SOC-Parent) 16512276 On-demand 0 SOC Case mgmt & SOAR
Oracle Get Incident and Close (SOC-Parent) b780643a On-demand 0 SOC Case mgmt & SOAR

5. Operational Notification Infrastructure

Category: Other

Subcategories: SaaS / IT administration

Description: Cross-cutting utility playbooks that provide error escalation via Microsoft Teams for every automation domain above — Claroty CTD operations, Sumo Logic flows, and XDome workflows each have a dedicated Teams error subflow. Executions of these playbooks reflect error handling overhead rather than primary business outcomes. Also includes a one-time Getting Started test workflow.

Note: The SubFlow - Send Error Message Via Teams SumoLogic recorded 15,073 executions in the bb1daa88 workspace — nearly matching the execution volume of the Sumo Logic Unacknowledged Insights notification scheduler (15,075). This 1:1 ratio suggests the primary Sumo Logic workflow was consistently encountering an error condition on almost every run during part of the year, warranting investigation.

Playbook Workspace Automation Type Executions (12 mo) Category Subcategory
Getting Started - Hello World 163d05d1 On-demand 1 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams bb1daa88 On-demand 47 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams SumoLogic bb1daa88 On-demand 15,073 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams XDome bb1daa88 On-demand 2 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams (SOC-Parent) 16512276 On-demand 4 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams SumoLogic (SOC-Parent) 16512276 On-demand 6 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams (SOC-Parent) b780643a On-demand 1 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams SumoLogic (SOC-Parent) b780643a On-demand 15 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams 5.0 bb1daa88 On-demand 1 Other SaaS / IT administration
SubFlow - Send Error Message Via Teams 5.0 (SOC-Parent) 16512276 On-demand 0 Other SaaS / IT administration

Key Observations

Strengths

Specialized OT security automation is the core differentiator. The dominant workload is OT/ICS-specific — Claroty CTD and XDome cover the industrial security layer while Sumo Logic serves as the SIEM aggregation point. This is a rare, mature automation pattern that directly addresses Rockwell's industrial cybersecurity mandate. The pipeline from OT sensor → Blink → SIEM → ITSM is fully wired.

Multi-workspace SOC hierarchy demonstrates operational maturity. Playbooks run across three distinct workspaces — one primary (bb1daa88) and two SOC-Parent environments (16512276, b780643a) — indicating a deliberate multi-site or multi-team operational design. The SOC-Parent workspaces together account for the majority of active executions, suggesting these are the live production environments.

Sumo Logic oversight automation runs continuously at scale. The unacknowledged insights notification cron (every 2 minutes, across 3 workspaces) logged 48,372 combined runs. This represents persistent, machine-enforced analyst accountability — every open SIEM alert has a defined follow-up cadence without manual process overhead.

Claroty CTD alert resolution is highly active. SubFlow Claroty CTD Resolve Alert recorded 1,343 combined executions (326 in workspace 16512276, 1,017 in b780643a) — the highest volume of any direct operational action, reflecting automated OT alert closure as the primary SOC activity.

Gaps & Risks

Sumo Logic error rate in primary workspace warrants investigation. SubFlow - Send Error Message Via Teams SumoLogic executed 15,073 times in workspace bb1daa88 — a near 1:1 ratio with the Sumo Logic Unacknowledged Insights notification scheduler in the same workspace (15,075). This strongly suggests the workflow was failing on nearly every run for an extended period. The SOC-Parent workspaces show much lower error rates (6 and 15 respectively), suggesting those environments operate more cleanly.

Oracle integration is built but has zero production executions. The full Oracle ticket automation (Sumo Logic Create Oracle Ticket + Oracle Get Incident and Close) across all three workspaces shows 0 executions. This path appears to be a configured but untriggered integration — either the trigger condition is never met or the integration was superseded by the SNOW workflow.

SIEM enrichment automation is significantly underutilized. Sumo Logic SIEM Enrichment Automation recorded only 8 total executions across active workspaces despite being a webhook-triggered event automation. This likely means the Sumo Logic enrichment webhook is either not configured to fire broadly, or insights are reaching closure without triggering the enrichment path — a potential coverage gap in alert context.

XDome automation is nascent. XDome Get Devices (1 execution), XDome Get Devices Related to Alerts (1 execution), and XDome Execution Scheduler (1 execution) show near-zero activity. XDome alert closure subflows have 0 executions across all workspaces. The integration exists but has not been operationalized at scale — representing an opportunity to extend coverage to the IoT/OT device layer.

Several "5.0" variant playbooks overlap with existing production flows. A set of "5.0"-suffixed playbooks (Claroty_CTD_Execute_Site_Metrics_Assets 5.0, Claroty CTD - Get Alert Count 5.0, etc.) coexist with their non-5.0 counterparts. Both versions appear active in some workspaces. Without clear versioning governance, this risks duplicate data collection, inconsistent behavior across sites, and compounding maintenance overhead.

Integration Ecosystem

Integration Role
Claroty CTD OT/ICS alert source, asset inventory, unsecured protocol detection, site metrics
XDome IoT/OT device inventory and alert-correlated device data
Sumo Logic Central SIEM — receives OT data, generates insights, drives alert closure and ticket creation
ServiceNow ITSM — receives security cases and health incidents from OT/SIEM events
Oracle Secondary ITSM — ticket creation and bidirectional closure (built, not yet active)
Microsoft Teams SOC analyst notification channel for unacknowledged alerts and error escalation
E New Integrations (detail) 0 added in last 30d

New Integrations Added - Last 30 Days

No new integrations found, or DB query was skipped.