Alert Logic Integration with DefectDojo
Alert Logic Integration with DefectDojo
Alert Logic, now part of Fortra, is a managed detection and response (MDR) provider whose platform also scans customer environments for vulnerabilities. Its console lists vulnerabilities by asset, with CVSS scores, CVE identifiers, evidence, and recommended resolutions, and the filtered list can be exported to CSV. DefectDojo imports those CSV exports, and DefectDojo Pro can also pull vulnerability exposures directly with the Alert Logic connector.
Alert Logic Integration with DefectDojo
Our Alert Logic contract covers detection and response, and the vulnerability scanning that comes with it finds real issues on our hosts. Those issues used to sit in the Alert Logic console where only the security team looked. Importing them into DefectDojo puts each vulnerability on the right Asset with its endpoints, CVSS score, and resolution, deduplicated on Alert Logic's own vulnerability ID, so infrastructure owners see them in the same queue and under the same SLAs as their other findings.
Why Alert Logic Matters
For teams that buy MDR, the bundled vulnerability scanning is often the main source of infrastructure findings.
- Alert Logic scans the hosts and services in the deployments it protects, and the export records the deployment, network, and asset type for each row.
- Each row carries a stable vulnerability ID, CVSS score, CVE, and resolution text, which is the information needed to act.
- Its exports flag vulnerabilities listed in CISA's Known Exploited Vulnerabilities catalog, which is a strong signal for prioritization.
- Exports and console views don't track ownership or remediation deadlines across your other tools. That part needs a vulnerability management platform.
Advantages of This Integration
- Stable deduplication. DefectDojo stores Alert Logic's
Vulnerability IDas the unique ID from tool, so repeat imports of the same vulnerability match instead of piling up. - Known exploited vulnerabilities stand out. Rows with
CISA Known Exploitedset to Yes get acisa-known-exploitedtag, ready for filters, dashboards, or a stricter SLA. - Real endpoints. Each address in the
IP Addresscolumn becomes an endpoint, with protocol and port fromProtocol/Port, so findings can be grouped by host. - Nothing dropped. All 26 CSV columns are used. Columns without a dedicated Finding field go into a structured description, including deployment, VPC or network, first seen, and last scanned.
- Two ways in. CSV import works in Community Edition and DefectDojo Pro. DefectDojo Pro adds an API connector that syncs exposures on a schedule.
How This Integration Works
Option 1: CSV import. In the Alert Logic console, go to Validate, then Vulnerabilities (or the equivalent vulnerability view), apply the filters you want, and export the list as CSV. The parser handles the UTF-8 byte-order mark Alert Logic adds and keeps multi-line Description, Evidence, and Resolution fields intact.
In DefectDojo, open an Engagement, choose Import Scan Results, select Alert Logic Scan, and upload the file. To automate the import, use the API:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=Alert Logic Scan"
-F "file=@alertlogic-vulnerabilities.csv"
-F "product_name=corp-infrastructure"
-F "engagement_name=Alert Logic"
-F "auto_create_context=true"
With DefectDojo Pro, Universal Importer works the same way:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "Alert Logic Scan"
--report-path "./alertlogic-vulnerabilities.csv"
--product-name "corp-infrastructure"
--engagement-name "Alert Logic"
--auto-create-context
Option 2: Alert Logic connector (DefectDojo Pro). Create an access key ID and secret key under Configure, API Keys in Alert Logic. In the DefectDojo Pro UI, add the Alert Logic connector and enter your region's API URL as the Location: https://api.cloudinsight.alertlogic.com for the US or https://api.cloudinsight.alertlogic.co.uk for the UK. Alert Logic is region-partitioned, so this must match your account. Enter the key ID and secret, optionally an Account ID (for managed-service parent accounts working on a child account), and optionally a Minimum Severity. DefectDojo exchanges the keys for a short-lived session token on each Sync and creates a Record for each Alert Logic deployment. The connector imports vulnerability exposures only. MDR incidents are out of scope.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in Alert Logic CSV | Notes |
|---|---|---|
| Title | Vulnerability | Truncated with "..." if over 500 characters |
| Severity | Severity | Critical, High, Medium, Low, Info map one to one; unrecognized is Info |
| CVSS v3 Score | CVSS Score | Parsed as a number; empty leaves no score |
| Component Name | Asset Name | The affected host or service |
| Endpoints | IP Address, Protocol/Port | One endpoint per address; port 0 omitted |
| Vulnerability IDs | CVE | Single CVE when present |
| Mitigation | Resolution | Multi-line text preserved |
| Unique ID from Tool | Vulnerability ID | Alert Logic's stable identifier |
| Description | Description, Evidence, Operating System, and other columns | Structured labeled block, empty fields skipped |
| Tags | CISA Known Exploited | cisa-known-exploited when the value is Yes |
| Active | Always true | Exports carry no mitigation status |
| Finding type | Static | Set for all rows |
| Deduplication | Unique ID or hashcode | Vulnerability ID, falling back to title, component_name, vuln_id_from_tool |
Use Cases
MDR plus internal remediation: The security team keeps Alert Logic for detection, but infrastructure teams fix vulnerabilities. Importing exposures into DefectDojo gives those teams assigned findings with deadlines instead of a monthly spreadsheet.
KEV-first patching: A team builds a filter on the cisa-known-exploited tag and gives those findings a shorter SLA, so actively exploited issues get handled before the rest of the backlog.
Multi-deployment reporting: With the Pro connector creating a Record per Alert Logic deployment, a security lead can compare open exposure across environments next to application findings for the same services.
Managed service providers: A provider using a parent Alert Logic account sets the connector's Account ID to work on a specific child account and keeps each customer's findings separate in DefectDojo.
Operational Tips
- Alert Logic CSV rows are always imported as active. Reimport each new export into the same Test so vulnerabilities missing from the latest export are mitigated.
- Apply the same console filters every time you export. Changing filters between exports makes reimport close findings that were only filtered out.
- The severity mapping expects Alert Logic's capitalized values (Critical, High, Medium, Low, Info). Anything else becomes Info, so check exports from custom views.
- The parser does not populate
vuln_id_from_tool, so when a row lacks a Vulnerability ID the fallback hash in practice compares title and asset name. - Use
minimum_severityor the connector's Minimum Severity to start with High and Critical. - Make sure the connector's Location matches your account's region. A US URL won't find a UK account.