> For the complete documentation index, see [llms.txt](https://docs.dropzone.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.dropzone.ai/integrations/alert/gem.md).

# Gem

{% hint style="info" %}
Gem is a Alert Source integration. The Dropzone platform creates Investigations based on alerts from Alert Sources.
{% endhint %}

Gem is a SIEM focusing on Cloud Detection and Response (CDR).

## Create an API Key

Dropzone requires a Gem Client ID and Client Secret.

To obtain these, follow the instructions available on Gem's [documentation site](https://docs.wiz.io/) for creating a Client ID and Client Secret.

## Enable Gem

To enable the Alert Source integration, do the following:

* Navigate to your Dropzone AI tenant home page e.g. https\://*mycompany*.dropzone.app
* In the bottom left hand corner, click Settings > Integrations

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-8c77435ef341f8180540e049f505d3390a27bbf4%2Fui-integrations-dropdown.png?alt=media" alt=""><figcaption><p>Integrations Dropdown</p></figcaption></figure>

* Click "Library"

{% hint style="info" %}
If you have previously integrated this application, click "Configured"
{% endhint %}

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-7e038b4f51ee27d4cf4f1ac6f76c5ddae2bf29c5%2Fapp_system_integrations_library.png?alt=media" alt=""><figcaption><p>Click Library</p></figcaption></figure>

* In the Search bar, search Gem, then click "Configure"

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-6a8832ed36e5467d4e7a652eb7736183cbf33175%2Fapp_system_integrations_available_Gem.png?alt=media" alt=""><figcaption><p>The Gem Alert Tile</p></figcaption></figure>

* Input your Gem server domain (e.g. *app.gem.security*, *eu-west-1.app.gem.security*)
* Input the Client ID and Client Secret you created earlier

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-ad63b49a9cbe4a820e1442e3bee7445dfbe02a84%2Fapp_system_integrations_available_Gem_config.png?alt=media" alt=""><figcaption><p>The Gem Alert Source Configuration (pt 1)</p></figcaption></figure>

* Input your desired poll interval and lookback
* Click "Comment Investigation Results to ticket" if you want Dropzone to push investigation results back to Gem

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-c0ec78db489c5c294e95314404db1160ff1c2db3%2Fapp_system_integrations_available_Gem_config-1.png?alt=media" alt=""><figcaption><p>The Gem Alert Source Configuration (pt 2)</p></figcaption></figure>

* If you wish to further filter alerts using the Python [CEL](https://python-common-expression-language.readthedocs.io/en/stable/tutorials/cel-language-basics/) package, check the box labeled "Use advanced filtering"
* Input your CEL expression, then select whether to include or exclude alerts matching that filter. Add each filter individually using the "Add Item" button
* Contact your Dropzone AI support representative for more information about this feature

<figure><img src="https://435022081-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmBVcKuiytGCsIDpL70BC%2Fuploads%2Fgit-blob-43a55827dfbfd5a9af3d744a16e7e8306fc8e253%2Fadvanced-filtering-test-save.png?alt=media" alt=""><figcaption><p>The Gem Alert Source Configuration (pt 3)</p></figcaption></figure>

* Click "Test & Save"

If you have any errors or questions, engage your Dropzone AI support representative.
