Skip to main content
This integration is currently in beta. Sandfly alert results are ingested as informational events as we finalize more detailed categorization mappings.
The Sandfly integration ingests Linux detection results from Sandfly and correlates them to host inventory in Wirespeed.

What This Integration Does

  • Ingests Sandfly alert results into Wirespeed detections
  • Syncs Sandfly hosts as endpoint assets
  • Correlates detections to endpoint inventory in Wirespeed for host context

Prerequisites

Before setup, make sure you have:
  1. The hostname or IP address of your Sandfly server (reachable from Wirespeed)
  2. A dedicated Sandfly API user with read-only access (recommended role: api_result_read)
  3. The API user’s username and password

Step 1: Create a Read-Only API User in Sandfly

In Sandfly, create a dedicated integration user and assign read permissions only (prefer api_result_read).
Use a dedicated service account for Wirespeed instead of a personal admin account.

Step 2: Add Sandfly in Wirespeed

  1. Go to Integrations > Add Integration
  2. Search for Sandfly
  3. Enter:
    • Sandfly Host (hostname or IP, no protocol/path; for example sandfly.company.com or 142.250.190.46)
    • API Username
    • API Password
  4. Click Integrate
During onboarding, Wirespeed validates:
  • Credential correctness (/v4/auth/login)
  • API reachability and token validity (/v4/version)

Detection Ingestion Behavior

  • Only alert status results are ingested
  • pass and error results are ignored
  • Whitelisted and superseded results are excluded
  • Cursor-based polling uses time_since to avoid gaps and duplicates

Endpoint Inventory and Enrichment

  • Host inventory sync uses Sandfly host summaries (/v4/hosts?summary=true)
  • Host context is attached to detections through Wirespeed endpoint correlation

Troubleshooting

Authentication or Validation Failures

Check:
  1. Hostname/IP is correct and reachable from Wirespeed
  2. Wirespeed can reach your Sandfly API over HTTPS
  3. Username/password are valid
  4. The API user has read access to results and hosts

No Detections Appearing

Check:
  1. Sandfly has recent alert results (not only pass/error)
  2. Results are not whitelisted or superseded
  3. Initial sync may take a few minutes depending on volume

Additional Resources