Torq
Bring your Torq SOC operations into the JupiterOne graph — cases with the lifecycle timestamps and SLA data behind resolution-time and case-volume reporting, the analysts they are assigned to, and the runbooks they follow. For workspaces licensed for Auto Triage (HyperSOC), alerts are ingested alongside, carrying the detection, acknowledgement and triage timestamps and the triage verdict that underpin acknowledgement-time, triage-latency and true-positive-rate reporting, each linked to the case it produced. The integration collects metadata only: case descriptions, analyst notes, comments, attachments and runbook bodies are never retrieved.
- Installation
- Authorization
- Data Model
- Types
Installation
Prerequisites
- A Torq workspace, and an API key created in it.
- If you want alert data, a workspace licensed for Auto Triage (HyperSOC). Case data does not require it — see Auto Triage is licensed separately.
- Access to JupiterOne with permission to configure integrations.
Create an API key in Torq
The integration authenticates using OAuth 2.0 (client credentials), exchanging the API key's Client ID and Client Secret for a bearer token. Tokens are valid for one hour and are renewed automatically during a run.
To create the key:
- Sign in to Torq.
- Go to Settings → API Keys.
- Create a new API key and copy the Client ID and Client Secret. The secret is shown only once.
An API key is scoped to the workspace it is created in, so a JupiterOne instance collects from exactly one Torq workspace. To cover several workspaces, create one integration instance per workspace.
The integration issues read-only requests.
Configuration in JupiterOne
To install the Torq integration in JupiterOne, navigate to the Integrations tab in JupiterOne and select Torq. Click New Instance to begin configuring your integration.
Creating an instance requires the following:
-
The Account Name used to identify the Torq account in JupiterOne. Ingested entities will have this value stored in
tag.AccountNamewhen theAccountNametoggle is enabled. -
Description to assist in identifying the integration instance, if desired.
-
Polling Interval that you feel is sufficient for your monitoring needs. You may leave this as
DISABLEDand manually execute the integration. -
The Authentication fields below.
Authentication fields
| Field | Required | Description |
|---|---|---|
| Region | Yes | The Torq region hosting your workspace. Choose EU only if you sign in at eu.torq.io; otherwise leave it as United States. |
| Client ID | Yes | Client ID of the Torq API key. |
| Client Secret | Yes | Client Secret paired with the Client ID. Shown only once when the key is created. |
Click Create once all values are provided to finalize the integration.
Region selects both the API and authentication hosts — api.torq.io and auth.torq.io for the United States, api.eu.torq.io and auth.eu.torq.io for Europe. An API key issued in one region will not authenticate against the other.
Data collection fields
These are optional and control how much history each run collects.
| Field | Default | Description |
|---|---|---|
| Case Lookback Days | 90 days | How far back to collect cases on each sync, by case creation date. Options are 30, 90, 180 and 365 days, or All time. |
| Alert Lookback Days | 30 days | How far back to collect Auto Triage alerts on each sync, by acknowledgement time. Options are 7, 30 and 90 days. Only applies when the Auto Triage Alerts ingestion source is enabled. |
Case Lookback Days is a rolling window over case creation date. A case created before the window is removed from JupiterOne on the next run, even if it is still open. Choose All time if you need the full history retained.
Torq does not serve alerts acknowledged more than 90 days ago, which is why Alert Lookback Days stops at 90.
Data sources
You can narrow what the integration collects from the instance's ingestion source settings.
| Ingestion source | Default | Data collected |
|---|---|---|
| Cases | Enabled | Torq cases with their lifecycle timestamps, severity, category and SLA, for resolution-time and case-volume reporting. |
| Users | Enabled | User accounts in the Torq workspace. |
| Roles | Enabled | Roles available in the workspace and the permission scopes they grant. |
| User Role Assignments | Enabled | Which role each Torq user holds. |
| Runbooks | Enabled | Case runbooks defined in the workspace. Metadata only — the runbook body is not retrieved. |
| Case Assignments | Enabled | Which Torq user each case is assigned to. |
| Case Runbooks | Enabled | Which runbook each case follows. |
| Auto Triage Alerts | Disabled | Alerts triaged by Torq Auto Triage that resulted in a case, carrying detection, acknowledgement and triage timestamps plus the triage verdict. |
| Alert Case Links | Disabled | Which case each Auto Triage alert produced. Requires Auto Triage Alerts. |
| Case Relations | Disabled | Parent, duplicate and blocking relations between cases. |
Relationships that span two sources are only created when both are enabled. Disabling Users, for example, does not stop cases being collected — it removes the assignment edges between them.
The three disabled sources
Auto Triage Alerts requires a workspace licensed for Auto Triage, and alerts are the highest-volume object in Torq — Auto Triage exists to collapse many alerts into far fewer cases. The collection is bounded in two ways: to alerts that actually produced a case, and to the configured lookback window. That keeps the volume close to case count rather than one to two orders of magnitude above it.
Alert Case Links depends on Auto Triage Alerts and adds no requests of its own.
Case Relations is disabled for cost rather than volume: Torq exposes links only per case, so enabling it issues one additional API request for every case collected.
Auto Triage is licensed separately
Auto Triage (HyperSOC) is a separately licensed Torq capability. On a workspace without it, the alert endpoints return 403, while cases, users, roles and runbooks are unaffected.
The integration is built for this. Setup validates the credentials by requesting a token and nothing more, so an unlicensed workspace configures normally. If Auto Triage Alerts is enabled on a workspace that lacks the licence, the step records a missing-permission warning and the run continues — the remaining sources are collected as usual.
What the integration does not collect
The integration is designed to collect the minimum needed for reporting and relationship mapping. It never retrieves:
- Case descriptions, titles, analyst notes, comments or attachments
- Resolution write-ups or case review notes
- Auto Triage narrative output — alert summaries, verdict justifications and suggested actions
- Runbook bodies
Cases are named by their Torq pretty ID (for example #4812) rather than their title, following the same convention as the ServiceNow and Jira integrations. Alert names are collected, because they are the detection rule name reported by the source security tool — for example Endpoint Detection - ldt — rather than analyst-authored text.
The case timeline, notes, comments and attachment endpoints are never called at all.
Next steps
Now that your integration instance has been configured, it will begin running on the polling interval you provided, populating data within JupiterOne. Continue on to our Instance management guide to learn more about working with and editing integration instances.
Additional resources
- Torq API overview — hosts, regions and rate limits
- Torq API authentication — creating an API key and the client credentials flow
- Query cases — the case fields this integration reads
- List alerts — the Auto Triage alert fields this integration reads
Endpoints
API endpoints that the integration makes requests to.
Show Endpoints (6)
GET /v1alpha/cases/runbooksGET /v1alpha/cases/{case_id}/linksGET /v1alpha/rolesGET /v1alpha/usersPOST /v1/triage/alerts/queryPOST /v1alpha/cases/query
Documentation Links
Links to provider documentation relevant to setup and configuration.
Show Documentation Links (6)
Per-Step Breakdown
Detailed authorization requirements for each ingestion step.
Show all steps (1)
| Step | Endpoints |
|---|---|
| Build Case Links | GET /v1alpha/cases/{case_id}/links |
Entities
The following entities are created:
| Resources | Entity _type | Entity _class |
|---|---|---|
| Account | torq_account | Account |
| Alert | torq_alert | Finding |
| Case | torq_case | Incident, Record |
| Role | torq_role | AccessRole |
| Runbook | torq_runbook | Record |
| User | torq_user | User |
Relationships
The following relationships are created:
Source Entity _type | Relationship _class | Target Entity _type |
|---|---|---|
torq_account | HAS | torq_user |
torq_alert | TRIGGERS | torq_case |
torq_case | ASSIGNED | torq_user |
torq_case | USES | torq_runbook |
torq_case | LINKS | torq_case |
torq_user | ASSIGNED | torq_role |
Torq Account
torq_account inherits from Account
| Property | Type | Description | Specifications |
|---|---|---|---|
apiBaseUrl * | string | null | The Torq Public API base URL this instance collects from, for example https://api.torq.io/public. | |
region * | string | null | The Torq region hosting the workspace: 'us' or 'eu'. Determines both the API and authentication hosts. |
Torq Alert
torq_alert inherits from Finding
| Property | Type | Description | Specifications |
|---|---|---|---|
acknowledgedOn * | number | null | When Auto Triage acknowledged the alert and began work. | |
alertType * | string | null | The detection type reported by the source tool, for example 'Endpoint Detection - ldt'. | |
caseClosedByKind * | string | null | What closed the case this alert produced: 'USER' for an analyst, or 'WORKFLOW' or 'SOCRATES' for automation. Null while the case is open. | |
categoryNames * | array | null | Every category Torq assigned the alert, ordered by dominance. The class-level category property carries only the first — the SDK's entity validator rejects an array there even though the data model documents one. | |
changedSeverity * | string | null | The severity the reviewing analyst substituted, when they changed it. Null when the severity was left as Auto Triage set it. | |
changedVerdictValue * | string | null | The verdict the reviewing analyst substituted, when they changed it. Null when the verdict was confirmed or never reviewed. | |
detectedOn * | number | null | When the source security tool detected the activity, before Torq received it. | |
ingestedOn * | number | null | When the alert arrived in the Torq workspace. | |
isAutoClosed * | boolean | null | Whether the case this alert produced was closed by automation rather than by an analyst. Null while the case is open. | |
isVerdictReviewed * | boolean | null | Whether an analyst reviewed the Auto Triage verdict rather than leaving it unexamined. | |
mitreTacticIds * | array | null | MITRE ATT&CK tactic IDs associated with the alert, for example 'TA0011'. | |
mitreTacticNames * | array | null | Names of the MITRE ATT&CK tactics associated with the alert, positionally aligned with mitreTacticIds. An entry Torq sends without a name repeats its id here. | |
mitreTechniqueIds * | array | null | MITRE ATT&CK technique IDs associated with the alert, for example 'T1566'. | |
mitreTechniqueNames * | array | null | Names of the MITRE ATT&CK techniques associated with the alert, positionally aligned with mitreTechniqueIds. An entry Torq sends without a name repeats its id here. | |
organizationId * | string | null | Identifier of the Torq organization the workspace belongs to. | |
prettyId * | string | null | The alert identifier as shown on the Torq Alerts page. | |
sourceIntegrationTypeId * | string | null | Identifier of the tool the alert came from, for example 'crowdstrike_streaming' or 'sentinelone_data_connector'. | |
sourceMitigation * | string | null | The mitigation the source tool applied or offered for the alert. | |
sourceSeverity * | string | null | The severity the source tool assigned, before Auto Triage reassessed it. | |
timeToAcknowledgeSeconds * | number | null | Elapsed seconds from source detection to Auto Triage acknowledgement. The per-alert input to mean time to acknowledge (MTTA). | |
timeToTriageSeconds * | number | null | Elapsed seconds from acknowledgement to a completed verdict — how long Auto Triage took to reach a decision. | |
triagedOn * | number | null | When Auto Triage finished assigning a verdict. | |
verdictConfidence * | string | null | How confident Auto Triage was in the verdict: 'High', 'Medium', or 'Low'. | |
verdictReviewAction * | string | null | What the reviewing analyst did: 'Confirmed' to agree with Auto Triage, or 'Changed' to override it. The rate of each measures analyst agreement with automated triage. | |
verdictTriageSeverity * | string | null | The severity Auto Triage assigned, as Torq reports it: 'Critical', 'High', 'Medium', 'Low', or 'Info'. The normalized form is on the severity property. | |
verdictValue * | string | null | The Auto Triage verdict: 'True Positive - Malicious', 'True Positive - Benign', or 'False Positive'. | |
verifiedByEmail * | string | null | Email address of the analyst who reviewed the verdict. | |
verifiedOn * | number | null | When the analyst reviewed the verdict. | |
workspaceId * | string | null | Identifier of the Torq workspace the alert belongs to. |
Torq Case
torq_case inherits from Incident, Record
| Property | Type | Description | Specifications |
|---|---|---|---|
accessPolicyType * | string | null | Who can open the case: 'ACCESS_POLICY_PUBLIC' for everyone in the workspace, or 'ACCESS_POLICY_COLLABORATORS_LIST' when it is restricted to named collaborators. | |
assigneeEmail * | string | null | Email address of the analyst the case is assigned to. Retained alongside the assignment relationship because the assignee may be someone who is not an ingested Torq user. | |
completedOn * | number | null | When the case moved to a resolved or closed state. Null while the case is still open. | |
isSlaBreached * | boolean | null | Whether the case took longer than its resolution SLA, measured from the SLA start. Computed for closed cases from the resolution time, and for open cases from the time elapsed so far, so a case that has already run over reports as breached before anyone closes it. Null when the case carries no SLA. | |
pendingTaskCount * | number | null | Number of tasks on the case still awaiting completion. | |
prettyId * | string | null | The case identifier as shown on the Torq Cases page, for example '#28'. | |
reporterKind * | string | null | What opened the case: 'USER', 'WORKFLOW', or 'SOCRATES' (Torq's AI agent). Distinguishes analyst-raised cases from automation-raised ones. | |
resolutionReason * | string | null | The short reason the case was resolved or closed, chosen from the workspace resolution reasons. The free-text resolution details are not ingested. | |
reviewConclusion * | string | null | The outcome of the case review, by default 'Approved' or 'Rejected', though workspaces can customise the set. | |
reviewedByEmail * | string | null | Email address of the analyst who actually recorded the review conclusion. | |
reviewerEmail * | string | null | Email address of the analyst assigned to review the case. | |
slaEndedOn * | number | null | When the resolution SLA timer stopped, which Torq reports as the time the case was resolved or closed. Null while the case is still open. | |
slaSeconds * | number | null | The resolution SLA in seconds: how long after creation the case is expected to be resolved or closed. | |
slaStartedOn * | number | null | When the resolution SLA timer started. Torq reports this as the time the case was created, and it is the baseline the breach calculation measures from. | |
timeToResolveSeconds * | number | null | Elapsed seconds from case creation to resolution or closure. The per-case input to mean time to resolve (MTTR). Null while the case is still open. |
Torq Role
torq_role inherits from AccessRole
| Property | Type | Description | Specifications |
|---|---|---|---|
isCustomRole * | boolean | null | Whether the role was defined by the workspace rather than being one of the roles Torq ships by default. |
Torq Runbook
torq_runbook inherits from Record
| Property | Type | Description | Specifications |
|---|---|---|---|
runbookId * | string | null | The Torq identifier of the runbook, as referenced by the cases that follow it. |
Torq User
torq_user inherits from User
| Property | Type | Description | Specifications |
|---|---|---|---|
isSsoProvisioned * | boolean | null | Whether the user was provisioned through the SSO identity provider rather than created locally in Torq. | |
lastLoginOn * | number | null | When the user last signed in to Torq, through either the UI or the API. |