gem.md
For the complete documentation index, see llms.txt. Markdown versions of documentation pages are available by appending .md to page URLs; this page is available as Markdown.
Gem
{% hint style="info" %} Gem is a Alert Source integration. The Dropzone platform creates Investigations based on alerts from Alert Sources. {% endhint %}
Gem is a SIEM focusing on Cloud Detection and Response (CDR).
Create an API Key
Dropzone requires a Gem Client ID and Client Secret.
To obtain these, follow the instructions available on Gem's documentation site for creating a Client ID and Client Secret.
Enable Gem
To enable the Alert Source integration, do the following:
- Navigate to your Dropzone AI tenant home page e.g. https://mycompany.dropzone.app
- In the bottom left hand corner, click Settings > Integrations
Integrations Dropdown
- Click "Available"
Click Available
- In the Search bar, search Gem, then click "Configure"
The Gem Alert Tile
- Input your Gem server domain (e.g. app.gem.security, eu-west-1.app.gem.security)
- Input the Client ID and Client Secret you created earlier
The Gem Alert Source Configuration (pt 1)
- Input your desired poll interval and lookback
- Click "Comment Investigation Results to ticket" if you want Dropzone to push investigation results back to Gem
The Gem Alert Source Configuration (pt 2)
- If you wish to further filter alerts using the Python CEL package, check the box labeled "Use advanced filtering"
- Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
- Contact your Dropzone AI support representative for more information about this feature
The Gem Alert Source Configuration (pt 3)
- Click "Test & Save"
If you have any errors or questions, engage your Dropzone AI support representative.