Workflows
Workflows provide a guided path through a Stellar Cyber capability or a related set of capabilities, from understanding what they do to configuring and using them in your environment.
Many capabilities in the Stellar Cyber Platform span several areas of the Knowledge Base. For example, identity threat detection involves connectors, sensors, detections, dashboards, investigation screens, and response actions, each documented in the section that owns it. That organization serves you well when you know what you are looking for. It serves you less well when you are adopting a capability for the first time and do not yet know which pieces you need or how they fit together.
Workflows solve that problem. Each one brings together the concepts, configuration, and operational guidance for a capability or solution and organizes them around the way you use them. Some workflows follow a sequential path from setup through daily operation. Others first explain a group of related capabilities and then provide guided procedures for the parts that form an operational workflow.
What a Workflow Gives You
Each workflow serves three purposes:
-
A summary of the capability or solution – What it does, what it detects or automates, how its components relate, and what coverage or benefit it provides. Read this to understand how it fits your environment.
-
A hub that connects to the Knowledge Base – Links to the topics that carry the full detail, organized around when and why you need them rather than where they live in the Knowledge Base.
-
A guide through configuration and operation – An organized path through the concepts and tasks you need to understand, configure, verify, and use the capability or solution.
How a Workflow Is Organized
The organization of each workflow reflects the capability or solution it describes.
Some workflows follow a sequence of stages, such as:
-
Understand – Learn what the capability does, what it detects or automates, and where its data or signals come from.
-
Connect and enable – Configure the data sources, connectors, settings, licenses, or other prerequisites the capability depends on.
-
Verify and tune – Confirm that the capability is working and adjust it for your environment.
-
Operate – Use the capability in daily investigation, triage, and response.
Other workflows cover a related set of capabilities that do not all belong to a single sequence. These workflows first explain how the capabilities fit together, then provide ordered steps or specialized procedures where a sequential workflow applies.
When a workflow includes numbered stages or steps, follow them in order unless the workflow indicates that a step is optional or can be performed independently.
Available Workflows
Workflows do not replace the reference material in the Knowledge Base. They lead you to it. When you need the full detail for a connector, a detection, or a screen, follow the links from the workflow to the topic that owns that subject.
