Triaging alerts
Alerts that match the criteria of the filters applied will appear at the top of the Triage area after clicking the Filter button.
After filtering alerts, users can perform the following actions:
Run an investigation from a filter
After applying a filter in the Triage area, you can create an investigation based on a group of suspicious alerts by clicking the Add to investigation button that appears at the top right corner of each group. All the alerts added to an investigation in this way will be stored in the Investigation list, which you can access by clicking the paper clip icon at the top right of the application.
Note that the investigation will not be created until you click the paper clip icon, select the required elements, and define the required investigation. Learn more about this in the Investigations section.
Check the details of a group of alerts
After filtering alerts in the Triage area, you can get both individual alerts or groups of alerts that share entities, which are grouped to make the analysis easier. In the case of groups, you can see the number of alerts in the group by checking the number in the lightning icon next to each group.
To obtain more details about the alerts in each group, click the name of the group in the Description column. You will access a window that shows a description in the top area, and 2 different areas: Timeline (the view that appears by default) and Associations (which you can access by clicking the button at the top right corner).
Alert states
When opening an alert in the Triage area clicking its Description name, we are actually opening a group of alerts (of course it could be only one alert in the group). These alerts are grouped by entities and by alert states. This state is UNREAD by default and it changes to WATCHED when we select one alert of the group.
It is important the difference between the state of the group and the state of each alert. If any of the alerts in a group are in UNREAD state, the group is also UNREAD. We can change the state of all the alerts of a group using the selector at the top right corner.
Increase the sighting count of an entity
The sighting count of an entity indicates the number of times that a specific entity has appeared in an investigation. This count can be manually increased by a user after filtering alerts. To do it, click the ? symbol next to the required entity in the top part of an alerts group. You will see a window that displays the number of times that entity has appeared in an investigation, as well as the first and last time it appeared. Click Submit to sighting now to increase the count by 1.
Note that this action cannot be undone.
Check the details of an entity
As shown above, each group of filtered alerts includes all the related entities on the top of the group. You can click the icon next to each entity to analyze its details.
Check the description of all the sections on this view in the table below. The numbers in the picture correspond to the sections in the table.
(1) Basic information | Basic information about the selected entity. The icon represents the entity type. You can also check the impact level of the entity and information about the in and out bytes of the entity. In some cases, the selected entity may have some similar entities that will also appear here, so you can navigate through them by clicking the required one. |
---|---|
(2) Related alerts and investigations | Here you can check the number of alerts and investigations that include this entity and the number of enrichments added to it, either in the Investigation list or the Investigation area. Click the enrichments count to display a series of graphs related to the enrichments related to the entity. See the section below for more information. |
(3) General details | General details of the entity, as well as the dates the entity was first and last seen. The information displayed in this area varies according to the entity type. |
(4) Impact and bytes in/out | A graph that shows the evolution of the entity's impact and its in and out bytes through time. You can hide elements by clicking them on the legend under the graph. This section does not appear in user-type entities. |
(5) List of related alerts | List of all the alerts that include the selected entity. |
(6) Related entities | This graph represents all the entities related to the one you selected. |
(7) List of related investigations | List of all the investigations that include the selected entity. Click an investigation name to access its details. |
If you click the enrichments count at the top of this area, you will display some extra graphs related to the enrichments linked to the selected entity:
(1) List of enrichments | A list that shows all the enrichments related to the selected entity. |
---|---|
(2) Enrichments timeline | A timeline that represents all the enrichments of the entity through time. |
(3) Machine learning evaluation enrichments | A couple of machine learning evaluations that show the security level of the entity and a client/server evaluation. |