ESET SOC Lite

Enter the dashboard access key to continue.

Incorrect key — try again.

Overview

Live pipeline status
connecting… DB AI Storage UDP TCP

Alerts Ingested

Risk Distribution

Pipeline Outcomes

Ingest Source

Live Pipeline Flow

Waiting Running Done Skipped Failed
Each incoming alert becomes a lane and advances through the pipeline in real time. Click any node for its detail.

Alerts

StatusRiskDetectionEndpoint SourceUpdatedCorrelation ID
No alerts yet. POST one to /webhook/eset — see API Docs.
Rows

AI-Generated Notifications

No AI content yet — it appears once an alert completes with status SUCCESS.

Monitor AI activity, data sent to models, external interactions, model outputs, and potential information exposure in real time.

AI Risk Breakdown

Live AI Activity

Same WebSocket as Pipeline Flow
No AI activity yet — it appears the moment an alert reaches the AI stage.

Recent AI Traces

Trace IDTimeComponentModel DurationStatusRisk
No AI traces yet — a trace is created every time an alert reaches the AI stage.
Every AI call in this application goes through here — see Trace Detail for the full input/output/security breakdown. Click a row to open it.

Mail Delivery

Checking mail service…

Email Outbox — Awaiting Handoff

TypeToSubjectRiskCreated
Outbox is empty — everything composed so far has been handed to the mail service.
These are waiting to be handed over. Once accepted (HTTP 202) the mail service owns delivery and its own retries.

Handoff History

StateTypeToSubject AttemptsService IDUpdated
No emails have been handed off yet.

Application Logs

Rows

Email Recipients

Saved to the database — applies to the next alert, no restart
Customer-facing summary and required confirmations.
Coordination notes plus a drafted client reply.
Detailed assessment and recommended actions.
Technical breakdown, unknowns, investigation items.
Comma-separated. Leave blank to skip that notification type.

AI Provider

Read-only — set per environment. The API key stays in the secret store.

Security posture

Runtime Configuration

Read-only — set in .env

Both ingest routes require the bearer token from ESET_WEBHOOK_AUTH_TOKEN and return a correlation_id immediately; the pipeline then runs in the background and appears live in Pipeline Flow.

Webhook
Syslog over HTTP
Syslog UDP / TCP
RFC 5424 frame containing a JSON object
Job status
Health

Example request


          
Replace $ESET_WEBHOOK_AUTH_TOKEN with your configured token.

Fields That Drive Behaviour

FieldEffect
severityLOW / MEDIUM / HIGH / CRITICAL — primary risk-engine input
threat_handledDowngrades risk when true
isolation_statusDowngrades a HIGH alert further when true
alert_id + occurred_atDeduplication key (falls back to a hash of the payload)
file_hash / ip_address / urlThreat-intel lookups (VirusTotal, AbuseIPDB); a MALICIOUS verdict raises the risk level
endpoint_type / endpoint_nameImportant endpoints (servers, domain controllers, IMPORTANT_ENDPOINT_PATTERNS) raise an unhandled detection one level
detection_name / raw_subject / raw_contentRansomware-like indicators or an outbreak make the alert CRITICAL
affected_endpoints / endpoint_countThe same detection on several endpoints makes the alert CRITICAL
Anything omitted normalizes to UNKNOWN rather than being invented.

Dashboard API

MethodEndpointPurpose
All dashboard routes require the X-Dashboard-Key header while an access key is configured.