Skip to content
How do I start smal...
 
Notifications
Clear all

How do I start small? Can I use OpenClaw just for enriching alerts before they hit the queue?

2 Posts
2 Users
0 Reactions
31 Views
(@charlotte0)
Reputable Member
Joined: 3 months ago
Posts: 241
Topic starter   [#15818]

I've been reading through the AI SOC forum for several weeks, trying to understand the practical entry points for implementing AI-assisted security operations. Our team is not ready for a full-scale agentic response system, but our alert fatigue is significant, particularly from our cloud infrastructure.

I am evaluating OpenClaw, as its local deployment model fits our data governance requirements. The documentation, however, primarily focuses on its end-to-end autonomous investigation capabilities.

My question is whether OpenClaw can be deployed in a limited, enrichment-only capacity. The goal would be to intercept raw alerts from our SIEM, use OpenClaw's LLM to:
* Correlate the alert with recent identity changes from our HRIS feed.
* Append a concise risk summary based on the user's department and accessed resource sensitivity.
* Add a recommended priority tier (e.g., P1-P4).

The enriched alert would then be delivered to our existing human analyst queue in the SOAR platform. This seems like a logical, controlled first step.

Has anyone implemented a similar phased approach? I am specifically looking for insights on:
* The configuration needed to disable autonomous response actions.
* How to structure the output schema so it cleanly appends to our existing alert objects.
* Any performance considerations when using it solely as an enrichment service, as opposed to a closed-loop system.

Our stack includes a standard SIEM, a cloud access security broker, and an identity provider. We have a Python-based internal orchestration layer that could handle the API calls to OpenClaw.



   
Quote
(@jenniferh)
Estimable Member
Joined: 3 months ago
Posts: 75
 

Yes, that phased approach is how we started. You're right about the docs, they push the full agent mode hard.

We configured it as an enrichment service. The key was setting `auto_investigate: false` in the core policy file and pointing our SIEM's webhook at the `/enrich` endpoint, not the main intake. It just JSON in, JSON out with the appended fields.

A caveat: you still need to tune the LLM prompts for your HRIS data schema. The out-of-box ones were too generic for our role-change terminology. Took a few days to stop getting useless "no relevant match found" summaries.


Trust but verify.


   
ReplyQuote