Label Packages

Label Packages are the collection of labelling rules. Labels are tags applied to each log message, used to characterize logs and group similar logs. For example, you can label all the login failed logs as failed. Using the label failed, you can group all the logs where the user failed to log in successfully. Labels can also be used to identify logs related to a specific threat technique or potential security attack.

../_images/LP_KB_LaP_Labels.png

Labels

In Logpoint, there are two types of Label Packages.

  1. Vendor Packages: The label packages bundled with the Logpoint installation.

  2. My Packages: The label packages that you add.

You can switch between My Packages and Vendor Packages by clicking the drop-down menu at the top-left corner.

Adding a Label Package

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Add.

../_images/LP_KB_LaP_AddIcon.png

Label Packages

  1. Enter Name and Description in Package Information.

../_images/LP_KB_LaP_Add_LabelPackages.png

Adding a Label Package

  1. Enter a Name and a Description in Package Information.

  2. Click Submit. Search Labels opens, containing all the existing search labels.

  3. Click Add to add a new label.

../_images/LP_KB_LaP_Add_LabelPak_SearchLabel.png

Search Labels Panel

  1. In Label Information, enter Search Query, select Package and enter List of Labels. Labels can contain only alphanumeric characters.

../_images/LP_KB_LaP_Add_LabelPak_SearchLabel_Add.png

Adding Search Label Information

  1. In Label Information, enter a Search Query, select a Package and enter a List of Labels.

  2. Click Submit.

In this example, all the log messages satisfying the search query device_ip = 127.0.0.1 are labeled with ip and device_ip.

Applying Labels with Label Package

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Manage Labels icon in Actions for the respective label.

../_images/LP_LabelPack_WithRules_List_Manage.png
  1. Click Add to open Search Label.

    Switch between the My Packages and the Vendor Packages by clicking the dropdown at the top-left corner of the panel.

Applying Labels from the Search Interface

  1. Go to Search and enter the query to which you want to add the labels.

  2. Click Search.

  3. Click Add Search To.

../_images/LP_LabelPack_AddFromSearch.png
  1. Select Labelling Rule to open the Search Label.

../_images/LP_LabelPack_AddFromSearch_Add.png
  1. Select a Package, and enter a List of labels.

  2. Click Submit.

Applying Labels using Normalization Signatures

You may need to add a label to particular types of logs or the logs collected by a specific device. For example, to add a label printer to all the logs collected from the printer, you can add a label to the signature of the normalization package that is used to normalize printer logs. This will add the label to all the logs processed by that normalization package.

  1. Go to Settings >> Knowledge Base and click Normalization Packages.

  2. Click Signatures in Actions.

    ../_images/LP_LabelPack_FromNormSig_List_ViewSig.png
  3. Click Edit Signature icon in Actions.

../_images/LP_LabelPack_FromNormSig_List_Edit.png
  1. Type label in the first textbox for Key Values.

  2. Enter a list of labels in the second textbox.

../_images/LP_LabelPack_FromNormSig_Add.png
  1. Type label in the first textbox for Key Value.

  2. Enter a list of labels in the second textbox and click Submit.

Note

You can also add labels while adding a normalization signature.

Applying Labels with Labeling Rules

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

../_images/LP_LabelPack_WithRules_List_Manage.png
  1. Click the Manage Labels icon in Actions for the respective label.

  2. Click Add to open Search Label.

../_images/LP_LabelPack_AddFromSearch_Add.png
  1. Enter a suitable Query, a Package Name, and a List of Labels.

  2. Click Submit.

In this example, all the log messages satisfying the search query device_name = localhost are labelled with Localhost and 127.0.0.1.

Exporting Label Packages

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

../_images/LP_KB_LaP_Export.png

Label Packages

  1. Select the label packages you want to export.

  2. Click Export.

The selected label package will be downloaded.

Importing Label Packages

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

../_images/LP_KB_LaP_Import.png

Label Packages

  1. Click Import.

  2. Browse to the label package.

  3. Click Submit.

Editing a Label Package

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

  2. Click the Name of the package that to edit and update the information.

../_images/LP_KB_LP_List_Edit.png

Label Packages

  1. Click Submit.

Activating Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Activate label package icon under Actions.

    ../_images/LP_KB_LP_List_Activate.png

    Label Packages

    1. To activate multiple Label Packages, select all the packages you want to activate. Click More and choose Activate Selected Packages.

    ../_images/LP_KB_LP_List_ActivateSelected.png

    Label Packages

    1. To activate all the Label Packages, click More and choose Activate All Packages.

    ../_images/LP_KB_LP_List_ActivateAll.png

    Label Packages

De-activating Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click De-activate label package icon under Actions.

    ../_images/LP_KB_LP_List_Deactivate.png

    Label Packages

    1. To deactivate multiple label packages, select all the packages you want to deactivate. Click More and choose Deactivate Selected Packages.

    ../_images/LP_KB_LP_List_DeactivateSelected.png

    Label Packages

    1. To deactivate all the label packages, click More and choose Deactivate All Packages.

    ../_images/LP_KB_LP_List_DeactivateAll.png

    Label Packages

Cloning Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click the Clone icon under Actions.

    ../_images/LP_KB_LP_List_Clone.png

    Label Packages

    1. To clone multiple label packages, select all the packages you want to clone. Click More and select Clone Selected Packages.

    ../_images/LP_KB_LP_List_CloneSelected.png

    Label Packages

    1. To clone all label packages, click More and select Clone All Packages.

    ../_images/LP_KB_LP_List_CloneAll.png

    Label Packages

  3. Enter new names for the cloned packages.

  4. Select Replace Existing? to replace an existing package with the same name.

../_images/LP_KB_LaP_ClonePanel.png

Clone Label Package Panel

  1. Click Clone.

Deleting Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Delete icon under Actions.

    ../_images/LP_KB_LP_List_Delete.png

    Deleting a Label Package

    1. To delete multiple Label Packages, select all the packages you want to delete. Click More and choose Delete Selected Packages.

    ../_images/LP_KB_LP_List_DeleteSelected.png

    Label Packages

    1. To delete all the Label Packages, click More and choose Delete All Packages.

    ../_images/LP_KB_LP_List_DeleteAll.png

    Label Packages

  3. Click Yes to confirm deletion.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support