Cybereason Analytics

Cybereason Search Template

The Cybereason search template provides dashboards consisting of predefined search queries with criteria and conditions to search for particular events and patterns in the incoming logs. There are two dashboards: Malops Overview and Malops Detection.

The Malops Overview dashboard provides a comprehensive view of detected malops, including information about the involved users, a timeline of malop events and the overall detection count.

_images/searchtemplates_view.png

Malops Overview

The Malops Detection dashboard provides in-depth insights into individual malops. It includes details such as a list of hosts with the highest malop detection, the primary root cause of the malop, administrative users with a significant number of malops and users who have experienced a high volume of malop events.

_images/searchtemplates_view1.png

Malops Detection

Viewing the Cybereason Search Template

  1. Go to Search Templates from the navigation bar.

  2. Select VENDOR SEARCH TEMPLATES from the drop-down.

  3. Click the clone icon from Actions.

_images/searchtemplates_view6.png

Cloning Cybereason Search Template

Logpoint forwards you to MY SEARCH TEMPLATE.

  1. Click CybeReason MalOps.

_images/searchtemplates_view2.png

Cybereason Search Template

Logpoint forwards you to Search Template View.

  1. Click Update to access the dashboards of the search template.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support