<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Alert Settings on Root Lock by HeartSuite</title><link>https://docs.heartsecsuite.com/docs/alerts/</link><description>Recent content in Alert Settings on Root Lock by HeartSuite</description><generator>Hugo</generator><language>en</language><atom:link href="https://docs.heartsecsuite.com/docs/alerts/index.xml" rel="self" type="application/rss+xml"/><item><title>SIEM and Fleet Integration</title><link>https://docs.heartsecsuite.com/docs/alerts/siem-integration/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.heartsecsuite.com/docs/alerts/siem-integration/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: Root Lock by HeartSuite integrates with your existing SIEM, EDR, and observability stack via syslog (journald/rsyslog) and webhook. This is the scale path for larger teams: configure once (in the Dashboard under Alert Settings → Fleet tab) and let your central tooling handle monitoring, correlation, and alerting. There is no requirement to run the TUI on every host for day-to-day fleet visibility.&lt;/p&gt;
&lt;p&gt;The raw enforcement decisions and higher-level alerts are emitted in real time. SIEM platforms receive the full picture; incident tools receive actionable events.&lt;/p&gt;</description></item><item><title>Central Policy Management and External Control</title><link>https://docs.heartsecsuite.com/docs/alerts/central-policy-management/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://docs.heartsecsuite.com/docs/alerts/central-policy-management/</guid><description>&lt;p&gt;&lt;strong&gt;Overview&lt;/strong&gt;: HeartSuite is designed to be driven by your existing central tooling. The Dashboard is the operator experience for a single host; enterprises use their control planes to manage policy and observe at scale.&lt;/p&gt;
&lt;p&gt;There is no built-in multi-host push from a HeartSuite server. Each host enforces its own allowlist, and Lockdown seals that allowlist on the device. Policy is applied per-host by your automation, with rich export surfaces for central consumption and attribution. This model lets you keep ownership of policy curation, change approval, and fleet-wide visibility inside the tools you already run (Ansible, Terraform, GitOps repositories, ServiceNow, Splunk, Elastic, custom orchestration).&lt;/p&gt;</description></item></channel></rss>