We don't have a lot of use cases. We supposed the MSSP provider would have a lot of use cases, and this intelligence would be used in the contract, but it wasn't the case.
We do have some specific situations like alerts in case of changes to extremely powerful accounts, administrative groups, and things like that.
Investigation is good when you know what you want to search for in Logger. The most difficult part is parsing the logs and configuring the parsers. For investigation, it's good. For correlation, it's not good. We use Sentinel, and Sentinel has pre-built use cases that are much easier to configure. So, it enhances our security incident investigation.
We have inbound integration, but configuring the parsers is sometimes very difficult. We only have two use cases where we have a correlation set up. We send the information to Check Point to block IP addresses when we see a lot of blocks from the same source. We have a trigger. So, Logger automatically blocks these IP addresses. We could have Logger put them on a blacklist.
So, it offers the ease of integration.