Connecting EDR and SIEM Platforms
You can connect your endpoint detection and response (EDR) software or Security Information and Event Management (SIEM) solution for agent discovery and monitoring.
The following EDR and SIEM platforms can be connected to Agentic Fabric:
- CrowdStrike Falcon Data Replicator
- Sumo Logic SIEM
Connecting CrowdStrike Falcon Data Replicator
Follow the Crowdstrike Falcon Data Replicator integration guide to create the credentials you'll need to connect the tool to Agentic Fabric.
-
In Agentic Fabric, enter a name for the source in the Source Name field.
-
In the SQS Queue URL field, enter the SQS URL from the CrowdStrike Falcon Console.
-
In the AWS Access Key ID field, enter your Client ID from the CrowdStrike Falcon Console.
-
In the AWS Secret Access Key field, enter your Secret from the CrowdStrike Falcon Console.
-
Select Test Connection to confirm the connection is successful.
-
Select Continue to continue setting up Agentic Fabric.
Connecting Sumo Logic SIEM
Agentic Fabric connects to the Sumo Logic Search Job API to execute queries and retrieve log results. This is a read-only integration using HTTP Basic authentication.
Before connecting Sumo Logic, ensure you have the following available:
- A Sumo Logic account
- Admin access to create roles, users, and access keys
- Service account with an Access ID and Access Key
- Correct search filter configured on the role
To connect Sumo Logic:
-
In Sumo Logic, create a role with the ability to create an access key.
-
Create a service account that is assigned the role you created.
-
In Sumo Logic, create an access key. Copy the Access ID and Access Key as you'll need them to connect Sumo Logic and Agentic Fabric.
-
In Agentic Fabric, enter a name for the source in the Source Name field.
-
In API URL field, enter your deployment-specific API v1 base URL. For information on API URLs, refer to SailPoint's Sumo Logic connector documentation.
-
In the Access ID field, enter the Access ID you received from creating an access key.
-
In the Access Key field, enter the access key you generated.
-
Select Test Connection to confirm the connection is successful.
-
Select Continue to continue setting up Agentic Fabric.
Troubleshooting Common Errors and Connection Issues
Common Errors
| Error | Platform | Cause | Fix |
|---|---|---|---|
| 403 Forbidden | Sumo Logic | Access key is invalid or role has restrictive search filter | Verify access key. Check role permissions and search filter. |
| Access Key shown once | Sumo Logic | Key was not saved at creation time | Delete the old key and create a new one. |
Common Connection Issues
If you experience issues during the connection test, try the following:
- Verify network connectivity: Ensure Agentic Fabric can reach the SIEM endpoint (no firewall blocking outbound HTTPS).
- Check credentials: Copy-paste errors are the most common cause of authentication failures.
- Test outside Agentic Fabric first: Use curl to confirm the endpoint responds before entering credentials in the wizard.
- Review audit logs: Check logs for failed API auth attempts for additional context.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.