Skip to main content

DFIR-IRIS

dfir-iris

Version: 1.0
Updated: August 21, 2026

DFIR-IRIS is an open-source collaborative incident response platform that enables security teams to manage cases, track indicators of compromise (IOCs), document assets, and maintain detailed incident timelines.

Actions

  • Add Asset to Case (Notification) - Adds an asset to an existing case for tracking and analysis.
  • Add IOC to Case (Notification) - Adds an indicator of compromise (IP address, domain, hash, etc.) to an existing case.
  • Add Note to Case (Notification) - Adds a note or comment to an existing case.
  • Add Timeline Event (Notification) - Adds a timeline event to document the chronology of an incident.
  • Close Case (Notification) - Closes an existing incident response case.
  • Create Alert (Notification) - Creates a new alert in DFIR-IRIS.
  • Create Case (Notification) - Creates a new incident response case.
  • Escalate Alert to Case (Notification) - Escalates an existing alert into a full incident case.
  • Get Case (Enrichment) - Retrieves details of a specific case.
  • List Cases (Enrichment) - Lists all cases.
  • List IOCs for Case (Enrichment) - Lists all indicators of compromise associated with a specific case.
  • Update Case (Notification) - Updates the details of an existing case.

DFIR-IRIS configuration

  1. Log in to your DFIR-IRIS instance.
  2. Click your username in the top-right corner and select My Settings.
  3. Copy the API key shown on the profile settings page.

Configure DFIR-IRIS in Automation Service and Cloud SOAR

Before you can use this automation integration, you must configure its authentication settings so that the product you're integrating with can communicate with Sumo Logic. For general guidance, see Configure Authentication for Automation Integrations.

How to open the integration's configuration dialog
  1. Access App Central and install the integration. (You can configure at installation, or after installation with the following steps.)
  2. Go to the Integrations page.
    Classic UI. In the main Sumo Logic menu, select Automation and then select Integrations in the left nav bar.
    New UI. In the main Sumo Logic menu, select Automation > Integrations. You can also click the Go To... menu at the top of the screen and select Integrations.
  3. Select the installed integration.
  4. Hover over the resource name and click the Edit button that appears.
    Edit a resource

In the configuration dialog, enter information from the product you're integrating with. When done, click TEST to test the configuration, and click SAVE to save the configuration:

  • Label. Enter the name you want to use for the resource.

  • IRIS URL. Enter the base URL of your DFIR-IRIS instance (e.g., https://iris.example.com).
  • API Key. Enter the DFIR-IRIS API key you copied earlier.
  • Verify Server Certificate. Select to validate the server’s SSL certificate.

  • Connection Timeout (s). Set the maximum amount of time the integration will wait for a server's response before terminating the connection. Enter the connection timeout time in seconds (for example, 180).

  • Automation Engine. Select Cloud execution for this certified integration. Select a bridge option only for a custom integration. See Cloud or Bridge execution.

  • Proxy Options. Select whether to use a proxy. (Applies only if the automation engine uses a bridge instead of cloud execution.)

    • Use no proxy. Communication runs on the bridge and does not use a proxy.
    • Use default proxy. Use the default proxy for the bridge set up as described in Using a proxy.
    • Use different proxy. Use your own proxy service. Provide the proxy URL and port number.
DFIR-IRIS configuration

For information about DFIR-IRIS, see DFIR-IRIS documentation.

Category

Incident Management

Change Log

  • August 21, 2026 (v1.0) - First upload
Status
Legal
Privacy Statement
Terms of Use
CA Privacy Notice

Copyright © 2026 by Sumo Logic, Inc.