Skip to main content

Sysdig

Sysdig is a comprehensive cloud-native security and observability platform that provides unified visibility, security monitoring, and threat detection across containerized environments, Kubernetes clusters, and cloud infrastructure. The platform specializes in runtime security, container security, vulnerability management, compliance monitoring, and performance optimization for modern cloud-native applications.

CategoryVulnerability management
DirectionQuery source
Sign-inAPI Token
Query languagesSTIX
Websitesysdig.com

Before you start​

Huntbase signs in to Sysdig with API Token. Create the credential in Sysdig first, then keep it to hand for the Connect step.

  1. Sign in to Sysdig Secure, not Sysdig Monitor.
  2. Select Settings from the user menu, then User Profile.
  3. Copy the Sysdig Secure API token shown there.
Watch out for
  • The token belongs to one user and team. Reset Token invalidates the old token immediately. For integrations, consider a team service account instead of a personal token.
  • Each query can cover a time range of up to 14 days.

For the vendor's own instructions, see Sysdig API token documentation.

tip

Use a dedicated, read-only credential for Huntbase where the product allows it. Huntbase only needs to read.

Connect Sysdig​

  1. Go to Connections and click New connection, or click New connection on the Sysdig product page.
  2. On Product, pick Sysdig and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Sysdig lives:

FieldRequiredNotes
Server AddressYesThe Sysdig Secure API endpoint for your region, such as secure.sysdig.com, us2.app.sysdig.com or eu1.app.sysdig.com. Don't use the website URL.
PortYes443. Defaults to 443.
Self-Signed Cert (PEM)NoProvide a self-signed or CA-signed certificate to securely communicate with the data source.

Credentials​

The only Method is API Token. Enter a Credential label (for example Production), then fill in:

FieldRequiredNotes
API TokenYesToken with readonly access to the Sysdig API. Secret — not shown again after you save it.

Query it​

Once connected, Sysdig can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​