Overview
Live pipeline status
connecting…
DB
AI
Storage
UDP
TCP
Alerts Ingested
Risk Distribution
Pipeline Outcomes
Ingest Source
Live Pipeline Flow
Waiting
Running
Done
Skipped
Failed
Each incoming alert becomes a lane and advances through the pipeline in real time. Click any node for its detail.
Alerts
| Status | Risk | Detection | Endpoint | Source | Updated | Correlation ID |
|---|
No alerts yet. POST one to /webhook/eset — see API Docs.
Rows
AI-Generated Notifications
No AI content yet — it appears once an alert completes with status SUCCESS.
Monitor AI activity, data sent to models, external interactions, model outputs, and potential information exposure in real time.
AI Risk Breakdown
Live AI Activity
Same WebSocket as Pipeline FlowNo AI activity yet — it appears the moment an alert reaches the AI stage.
Recent AI Traces
| Trace ID | Time | Component | Model | Duration | Status | Risk |
|---|
No AI traces yet — a trace is created every time an alert reaches the AI stage.
Every AI call in this application goes through here — see Trace Detail for the full input/output/security breakdown. Click a row to open it.
Mail Delivery
Checking mail service…
Email Outbox — Awaiting Handoff
| Type | To | Subject | Risk | Created |
|---|
Outbox is empty — everything composed so far has been handed to the mail service.
These are waiting to be handed over. Once accepted (HTTP 202) the mail service owns delivery and its own retries.
Handoff History
| State | Type | To | Subject | Attempts | Service ID | Updated |
|---|
No emails have been handed off yet.
Application Logs
Rows
Email Recipients
Saved to the database — applies to the next alert, no restartCustomer-facing summary and required confirmations.
Coordination notes plus a drafted client reply.
Detailed assessment and recommended actions.
Technical breakdown, unknowns, investigation items.
Comma-separated. Leave blank to skip that notification type.
AI Provider
Read-only — set per environment. The API key stays in the secret store.Security posture
Runtime Configuration
Read-only — set in .envSending Alerts
Open OpenAPI explorer ↗Both ingest routes require the bearer token from ESET_WEBHOOK_AUTH_TOKEN and return a correlation_id immediately; the pipeline then runs in the background and appears live in Pipeline Flow.
Webhook
Syslog over HTTP
Syslog UDP / TCP
RFC 5424 frame containing a JSON object
Job status
Health
Example request
Replace $ESET_WEBHOOK_AUTH_TOKEN with your configured token.
Fields That Drive Behaviour
| Field | Effect |
|---|---|
| severity | LOW / MEDIUM / HIGH / CRITICAL — primary risk-engine input |
| threat_handled | Downgrades risk when true |
| isolation_status | Downgrades a HIGH alert further when true |
| alert_id + occurred_at | Deduplication key (falls back to a hash of the payload) |
| file_hash / ip_address / url | Threat-intel lookups (VirusTotal, AbuseIPDB); a MALICIOUS verdict raises the risk level |
| endpoint_type / endpoint_name | Important endpoints (servers, domain controllers, IMPORTANT_ENDPOINT_PATTERNS) raise an unhandled detection one level |
| detection_name / raw_subject / raw_content | Ransomware-like indicators or an outbreak make the alert CRITICAL |
| affected_endpoints / endpoint_count | The same detection on several endpoints makes the alert CRITICAL |
Anything omitted normalizes to UNKNOWN rather than being invented.
Dashboard API
| Method | Endpoint | Purpose |
|---|
All dashboard routes require the X-Dashboard-Key header while an access key is configured.