Integration Types in BitLyft AIR®
BitLyft AIR® offers a flexible, modular approach to integrating with your security ecosystem. Integrations in BitLyft AIR® are categorized into four distinct types, each designed to perform a specific function within your security operations workflow:
Log Ingestion & Analytics
Remediation
Log Enrichment
Platform
Each integration type plays a unique role in enabling detection, investigation, and response across your environment. Below is a breakdown of each category.
1. Log Ingestion & Analytics
Purpose:
Collect log data from your systems and apply rules or policies to generate alerts.
Use Cases:
Ingest logs from Microsoft 365, cloud platforms, and identity providers.
Define detection rules or policies to analyze log data in real-time
Automatically generate alerts when suspicious behavior is detected
How it Works:
These integrations are responsible for securely pulling or receiving log data into the BitLyft AIR® platform. Once ingested, logs are parsed, normalized, and analyzed against defined detection content (rules and correlation logic). Alerts are created based on matching criteria, allowing security teams to take action quickly.
Examples:
Microsoft 365 Audit Logs
Identity Providers (IDP) telemetry
2. Remediation (Actions & Playbooks)
Purpose:
Execute automated incident response actions or playbooks to mitigate threats.
Use Cases:
Resetting compromised user credentials
Disabling access for suspicious accounts
Phishing emails
How it Works:
Remediation integrations connect to third-party systems and expose actions that can be triggered manually or automatically by playbooks. These can range from simple one-step responses to complex, multi-step workflows. Each action is logged and traceable for auditing and compliance.
Examples:
Microsoft 365: Reset Password
Okta: Suspend Device
Duo: Get Authentication Logs
One Login: Lock User Account
3. Log Enrichment
Purpose:
Enhance ingested log data with external or contextual information to improve alert accuracy and investigation.
Use Cases:
Add GeoIP data to network connection logs
Enrich IPs/domains with threat intelligence reputation scores
Correlate IOCs with known malicious indicators
How it Works:
Enrichment integrations operate passively in the background. When a relevant field (e.g., IP address, domain, file hash) is detected in log data or alerts, BitLyft AIR® queries external sources to append context. This information is visible in the alert details and is used in playbooks or during analyst investigations.
Examples:
MaxMind GeoIP
VirusTotal
AlienVault
4. Platform
Purpose:
Connect BitLyft AIR® to external platforms that provide services such as alert ingestion, SIEM functionality, or log storage.
Use Cases:
Integrate with Graylog for centralized alert handling
Ingest alert data from third-party detection platforms
Provide log forwarding to external systems
How it Works:
Platform integrations facilitate the overall interoperability of BitLyft AIR® with the customer’s broader security architecture. These integrations enable BitLyft AIR® to provide automated incident response.
Examples:
Graylog
Summary Table
Integration Type | Function | Examples |
|---|---|---|
Log Ingestion | Collect logs, generate alerts via policies | Microsoft 365 |
Remediation | Execute response actions or playbooks | Microsoft 365, Okta |
Log Enrichment | Add context to data (GeoIP, threat intel) | VirusTotal, MaxMind |
Platform | Connect to SIEMs and alerting platforms | Graylog |
Managing Integrations in BitLyft AIR®
You can view, enable, configure, or disable integrations from the Integrations section in the BitLyft AIR® web console. Each integration includes:
A summary of its capabilities
Required credentials or API tokens
Status indicators (Connected, Disconnected, Error)
Documentation links for setup guidance