コンテンツにスキップ

CSIRT-Pro Documentation

CSIRT-Pro is a cloud-native, unified security platform for SOC and CSIRT teams.

It covers the full security operations workflow in one platform, from log ingestion and threat detection through incident response and automation.


Core Capabilities

Capability Description
Search Real-time log search and visualization with PRQL
Case Management Thread-based incident tracking with AI-assisted similar-case search
Playbook (SOAR) Visual flow editor to automate detection through response
Pipeline (Log Ingestion) Ingest, parse, and normalize logs from any source
UEBA Management of scheduled detection Playbook tasks for users and entities
Dashboards Custom dashboards for at-a-glance security posture
Threat Intelligence CVE search (NVD), IOC lookup, and MITRE ATT&CK
Integrations Catalog to enable or disable integration packages
AI Investigate Read-only AI assistant that searches and aggregates logs and cases from natural language

Getting Started

  1. Why CSIRT-Pro covers the product's differentiators and how it compares to legacy SIEMs.
  2. Quick Start takes you from log ingestion to your first search.
  3. Migration from Splunk and Migration from Elastic describe how to transition from an existing SIEM.

Documentation Map

Section Audience Content
Why CSIRT-Pro Evaluators Product differentiators and SIEM comparison
Quick Start New users Setup and first workflow
User Guides (Search, Cases, Playbook, Pipeline, UEBA, Dashboards, Integrations) All users Detailed feature guides
API Reference Developers REST API specification
Security Checklist IT / Compliance Enterprise security and compliance checklist

Platform Architecture

CSIRT-Pro is delivered as a set of services, each responsible for a distinct part of the platform.

Layer Role
Log Storage Columnar log analytics store, schema-on-read (raw logs kept in a messages column, fields extracted at query time)
Query Language PRQL (Pipelined Relational Query Language)
Core API High-throughput, low-latency native service for search, ingestion, authentication checks, and rate control
Streaming Ingestion Message bus that buffers ingested logs before they are written to the analytics store
Ingestion Pipeline Worker tier that parses incoming logs and writes them to the analytics store
Web UI Browser-based console
Management API Organizations, users, ingestion definitions, Playbooks, UEBA settings, integrations, and billing
Real-time Notifications / AI Notification service and the generative-AI assistant backend
Authentication OIDC-based identity provider (IdP), with limited Passkey / WebAuthn support
Multi-tenancy Per-organization logical isolation: each organization is provisioned a dedicated user and dedicated views; customers cannot access the data store directly

Customer data and analytics processing remain within Japan, on a managed cloud in a domestic region.