CSIRT-Pro Documentation
CSIRT-Pro is a cloud-native, unified security platform for SOC and CSIRT teams.
It covers the full security operations workflow in one platform, from log ingestion and threat detection through incident response and automation.
Core Capabilities
| Capability | Description |
|---|---|
| Search | Real-time log search and visualization with PRQL |
| Case Management | Thread-based incident tracking with AI-assisted similar-case search |
| Playbook (SOAR) | Visual flow editor to automate detection through response |
| Pipeline (Log Ingestion) | Ingest, parse, and normalize logs from any source |
| UEBA | Management of scheduled detection Playbook tasks for users and entities |
| Dashboards | Custom dashboards for at-a-glance security posture |
| Threat Intelligence | CVE search (NVD), IOC lookup, and MITRE ATT&CK |
| Integrations | Catalog to enable or disable integration packages |
| AI Investigate | Read-only AI assistant that searches and aggregates logs and cases from natural language |
Getting Started
- Why CSIRT-Pro covers the product's differentiators and how it compares to legacy SIEMs.
- Quick Start takes you from log ingestion to your first search.
- Migration from Splunk and Migration from Elastic describe how to transition from an existing SIEM.
Documentation Map
| Section | Audience | Content |
|---|---|---|
| Why CSIRT-Pro | Evaluators | Product differentiators and SIEM comparison |
| Quick Start | New users | Setup and first workflow |
| User Guides (Search, Cases, Playbook, Pipeline, UEBA, Dashboards, Integrations) | All users | Detailed feature guides |
| API Reference | Developers | REST API specification |
| Security Checklist | IT / Compliance | Enterprise security and compliance checklist |
Platform Architecture
CSIRT-Pro is delivered as a set of services, each responsible for a distinct part of the platform.
| Layer | Role |
|---|---|
| Log Storage | Columnar log analytics store, schema-on-read (raw logs kept in a messages column, fields extracted at query time) |
| Query Language | PRQL (Pipelined Relational Query Language) |
| Core API | High-throughput, low-latency native service for search, ingestion, authentication checks, and rate control |
| Streaming Ingestion | Message bus that buffers ingested logs before they are written to the analytics store |
| Ingestion Pipeline | Worker tier that parses incoming logs and writes them to the analytics store |
| Web UI | Browser-based console |
| Management API | Organizations, users, ingestion definitions, Playbooks, UEBA settings, integrations, and billing |
| Real-time Notifications / AI | Notification service and the generative-AI assistant backend |
| Authentication | OIDC-based identity provider (IdP), with limited Passkey / WebAuthn support |
| Multi-tenancy | Per-organization logical isolation: each organization is provisioned a dedicated user and dedicated views; customers cannot access the data store directly |
Customer data and analytics processing remain within Japan, on a managed cloud in a domestic region.