GETTING STARTED

Your first alert in minutes

Strix turns the alerts your security tools already produce into scored, triaged cases — automatically. Connect a source, send one detection, and watch it flow all the way to a case with a Jira ticket and an SLA clock.

The path to your first alert

Three steps, the same for every source. The only difference is how each tool is told to send.

1 · Connect a source

Add Wazuh, Splunk, or Microsoft Sentinel in Integrations and copy its one-time webhook URL — a unique, tokenised endpoint scoped to your org.

2 · Send an alert

Point your tool at that URL. Each detection it fires is POSTed to Strix as it happens — no polling, and no Strix agent to host.

3 · Watch it triage

Alerts land in the Inbox, get scored, and critical ones auto-open a case with a Jira ticket and an SLA clock — no manual sorting.

Step by step

  1. 1

    Sign in to your workspace

    Open Strix and sign in. Each account belongs to one organization — your team, assets, integrations, and cases all live inside it. Don't have a workspace yet? Book a demo and we'll provision one for you.

    https://strix.redswordsecurity.com
  2. 2

    Connect your first data source

    Go to Integrations and connect Wazuh, Splunk, or Microsoft Sentinel. Strix reveals a webhook URL with an embedded token — copy it now, it is shown only once. Full per-source instructions, field maps, and troubleshooting live in the Integrations guide.

  3. 3

    Point your tool at Strix and fire an alert

    Configure your source to POST to that webhook (a manager integration for Wazuh, a webhook alert action for Splunk, a Logic App for Sentinel). Trigger one detection so a real alert flows end to end.

  4. 4

    Run Test Connection & admit your host

    Back on the source's card, click Test Connection — Strix runs a sample through the same normalizer a live alert uses and flags any missing fields. Then, under Integrations → SIEM Hosts, Admit the reporting host if it shows as Pending. Hosts are admitted, not auto-trusted, so a noisy or spoofed hostname can't silently enter your inventory.

  5. 5

    Watch your first alert triage itself

    Open the Alert Inbox. Your detection appears with its title, severity, and MITRE mapping, grouped by signature so repeats collapse into one line. A critical detection (Wazuh rule level ≥ 12, or High severity from Splunk/Sentinel) auto-opens a Case — seeded with remediation tasks, a linked Jira ticket, and a staged SLA timeline.

Need the exact steps for your tool? The Integrations guide has full instructions, field mappings, and troubleshooting for each source.

Integration guides

Meet your workspace

A quick tour of where things live once alerts start flowing.

Alert Inbox

Every source's alerts in one queue, scored and grouped by signature. Where you triage day to day.

Assets & SIEM Hosts

Your inventory of reporting hosts. Admit new SIEM hosts here before they enter the asset list.

Cases

Critical alerts become cases with tasks, a Jira ticket, an SLA clock, and evidence-gated verification.

Remediation

Track fixes to completion — AI-generated remediation steps, OS commands, and verification checks.

Reports

Device remediation reports and executive posture rollups, exportable to PDF and archived automatically.

Integrations

Connect and manage alert sources, Jira case-tracking, and Slack notifications. Rotate or revoke anytime.

Settings & Team

Invite teammates, set roles, and configure your org. Manage tokens and notification destinations.

ROLES & ACCESS

Who can do what

Strix keeps org control simple: two roles. New teammates join as Analyst and can request elevation to Admin, which an existing admin approves.

Admin

Full control of the org — manage integrations and billing, invite and remove teammates, set roles, and assign cases to people or teams. The role that owns setup.

Analyst

The default member role — triage the inbox, work and comment on cases, and generate reports. Everything an analyst needs day to day, without org-level settings.

Best practices

  • Start with a single source and prove one alert end to end before connecting more.
  • Set a meaningful severity on your detections — only critical alerts auto-open cases and Jira tickets.
  • Admit only hosts you recognise under SIEM Hosts; leave unknown ones Pending.
  • Use Test Connection after any change — it surfaces missing fields before they cost you a real alert.
  • Connect Jira early so cases sync two-way from the first critical detection.
  • Treat each webhook URL like a password; rotate it immediately if it leaks.

Frequently asked

Minutes once your source is connected. Wazuh and Splunk connect in ~10–15 minutes; Microsoft Sentinel takes a little longer because it uses a Logic App. After that, alerts arrive the moment your tool fires a detection.

Ready to connect your first source?

Go to Integration guides

Have your tools ready? Connect Strix and see your first alert.

Book Demo