Team & deployment setups · 7 min read

Set up Linivo for a security operations team

Configure Linivo as a detection source feeding a SOC, with the right routing, retention and access model for that workflow.

What you'll need

  • Admin role
  • A SIEM or ticketing destination if detections should flow onward
1

Route detections, not all alerts, to the SOC queue

Under Detections > Routing, send security-category detections (lateral movement, port scan, rogue device) to your SOC's channel or ticketing queue, and keep general performance alerts on a separate rotation.

2

Extend detection log retention

Set detection and access-log retention to match your incident-response and audit requirements under Settings > Data > Retention; this is typically longer than the default retention for routine performance metrics.

3

Set read-only access for analysts

Give SOC analysts the Auditor role: full visibility into detections, topology and logs, without the ability to change device configuration or alert thresholds.