Varonis · Arazzo Workflow
Varonis Investigate and Close Alert
Version 1.0.0
Pull events for a known alert, document findings as a note, then close it.
View Spec
View on GitHub
Cloud SecurityComplianceData AnalyticsData GovernanceData SecurityThreat DetectionArazzoWorkflows
Provider
Workflows
investigate-and-close-alert
Review a single alert's events, add a findings note, and close it.
Loads the events for a supplied alert id, records an investigation note as an audit trail entry, and closes the alert with the provided close reason.
1
getEvents
getAlertedEvents
Retrieve the forensic events for the supplied alert id so the analyst can review the activity that triggered the detection.
2
addFindingsNote
addAlertNote
Append the investigation findings to the alert as a note so the rationale for closing is preserved in the audit trail.
3
closeAlert
closeAlert
Close the alert with the provided close reason to track the resolution pattern.
Source API Descriptions
Arazzo Workflow Specification
Work with this as data
Every workflow here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for arazzo workflows
4 MCP tools reach this
find_arazzoBrowse and filter every workflow in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This workflow
curl "https://apis.io/api/v1/arazzo/varonis-investigate-and-close-alert-workflow"
All arazzo workflows
curl "https://apis.io/api/v1/arazzo?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.