Adaptive Shield
Connect Adaptive Shield to Radiant Security to forward SaaS security posture alerts for AI triage.
Last updated
Was this helpful?
Connect Adaptive Shield to Radiant Security to forward SaaS security posture alerts for AI triage.
Adaptive Shield is a SaaS Security Posture Management (SSPM) platform that monitors SaaS applications for misconfigurations, identity risks, and threat activity that can lead to account takeover, data exposure, and unauthorized access. Connecting Adaptive Shield forwards SaaS security and audit alerts to Radiant Security via webhook, using Adaptive Shield's Splunk HTTP Event Collector (HEC) event destination. Radiant uses these alerts to surface SaaS-layer threats during AI triage, correlating posture and identity signals with endpoint, network, and email activity already in the pipeline.
Log in to Radiant Security.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select Adaptive Shield Webhook, then click Data Feeds.
Under Select your data feeds, select Adaptive Shield Webhook and click Credentials.
In the Credential Name field, enter an identifiable name (e.g., Adaptive Shield webhook credentials).
In the Connector tag field, enter any string. Radiant uses this value as salt when generating the authentication token for your connector.
Click Add Connector.
On the Data Connectors page, find the new connector and click View Details. Under Vendor Configuration, copy and save the Webhook URL and Token. You will paste both into the Adaptive Shield console in the next section.
Log in to the Adaptive Shield console.
Navigate to Settings > Event Destination.
Click Add a New Event Destination.
Select Splunk.
Enter a name for the integration (e.g., RadiantSecurityConnector).
Enter the following details:
HEC URL: Paste the Webhook URL you copied from Radiant Security.
Token: Paste the Token you copied from Radiant Security.

Click Next, then click Test the connection.
Click Finish.
After Adaptive Shield begins forwarding, confirm events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by rs_connectorType:"adaptive_shield_webhook".
Confirm recent events appear.
Allow several minutes for events to be parsed, indexed, and available for search.
Last updated
Was this helpful?
Was this helpful?