Your first alert in minutes
Strix turns the alerts your security tools already produce into scored, triaged cases — automatically. Connect a source, send one detection, and watch it flow all the way to a case with a Jira ticket and an SLA clock.
The path to your first alert
Three steps, the same for every source. The only difference is how each tool is told to send.
1 · Connect a source
Add Wazuh, Splunk, or Microsoft Sentinel in Integrations and copy its one-time webhook URL — a unique, tokenised endpoint scoped to your org.
2 · Send an alert
Point your tool at that URL. Each detection it fires is POSTed to Strix as it happens — no polling, and no Strix agent to host.
3 · Watch it triage
Alerts land in the Inbox, get scored, and critical ones auto-open a case with a Jira ticket and an SLA clock — no manual sorting.
Step by step
- 1
Sign in to your workspace
Open Strix and sign in. Each account belongs to one organization — your team, assets, integrations, and cases all live inside it. Don't have a workspace yet? Book a demo and we'll provision one for you.
https://strix.redswordsecurity.com - 2
Connect your first data source
Go to Integrations and connect Wazuh, Splunk, or Microsoft Sentinel. Strix reveals a webhook URL with an embedded token — copy it now, it is shown only once. Full per-source instructions, field maps, and troubleshooting live in the Integrations guide.
- 3
Point your tool at Strix and fire an alert
Configure your source to POST to that webhook (a manager integration for Wazuh, a webhook alert action for Splunk, a Logic App for Sentinel). Trigger one detection so a real alert flows end to end.
- 4
Run Test Connection & admit your host
Back on the source's card, click Test Connection — Strix runs a sample through the same normalizer a live alert uses and flags any missing fields. Then, under Integrations → SIEM Hosts, Admit the reporting host if it shows as Pending. Hosts are admitted, not auto-trusted, so a noisy or spoofed hostname can't silently enter your inventory.
- 5
Watch your first alert triage itself
Open the Alert Inbox. Your detection appears with its title, severity, and MITRE mapping, grouped by signature so repeats collapse into one line. A critical detection (Wazuh rule level ≥ 12, or High severity from Splunk/Sentinel) auto-opens a Case — seeded with remediation tasks, a linked Jira ticket, and a staged SLA timeline.
Need the exact steps for your tool? The Integrations guide has full instructions, field mappings, and troubleshooting for each source.
Integration guidesMeet your workspace
A quick tour of where things live once alerts start flowing.
Alert Inbox
Every source's alerts in one queue, scored and grouped by signature. Where you triage day to day.
Assets & SIEM Hosts
Your inventory of reporting hosts. Admit new SIEM hosts here before they enter the asset list.
Cases
Critical alerts become cases with tasks, a Jira ticket, an SLA clock, and evidence-gated verification.
Remediation
Track fixes to completion — AI-generated remediation steps, OS commands, and verification checks.
Reports
Device remediation reports and executive posture rollups, exportable to PDF and archived automatically.
Integrations
Connect and manage alert sources, Jira case-tracking, and Slack notifications. Rotate or revoke anytime.
Settings & Team
Invite teammates, set roles, and configure your org. Manage tokens and notification destinations.
Who can do what
Strix keeps org control simple: two roles. New teammates join as Analyst and can request elevation to Admin, which an existing admin approves.
Admin
Full control of the org — manage integrations and billing, invite and remove teammates, set roles, and assign cases to people or teams. The role that owns setup.
Analyst
The default member role — triage the inbox, work and comment on cases, and generate reports. Everything an analyst needs day to day, without org-level settings.
Best practices
- Start with a single source and prove one alert end to end before connecting more.
- Set a meaningful severity on your detections — only critical alerts auto-open cases and Jira tickets.
- Admit only hosts you recognise under SIEM Hosts; leave unknown ones Pending.
- Use Test Connection after any change — it surfaces missing fields before they cost you a real alert.
- Connect Jira early so cases sync two-way from the first critical detection.
- Treat each webhook URL like a password; rotate it immediately if it leaks.
Frequently asked
Ready to connect your first source?
Go to Integration guides