Document toolboxDocument toolbox

Synthetic data: Injection for Windows Activity AB

Purpose

The firewall injection for Windows Activity AB is used in the Use Case: Windows Activity AB. This injection is composed of a short file to provide synthetic sample data on tables box.winlearn more and box.all.winlearn more, which also serve to test Windows Activity AB use case. The injection is continuous (starts over after injecting the last event) and the events are sent at a frequency of 1 second.

Open synthetic data

Once the synthetic data has been launched, you can use the Open button at the top right of the card in Exchange to access the search window, where you can check the data table with the synthetic data. You can also access the data table using finders or LINQ via the Navigation pane (Data Search area → Explore your data tab).

Use synthetic data

After launching the synthetic data, you can use it in various contexts, such as the search window to perform operations to analyze the data, Activeboards to visualize and analyze the data graphically, or alerts to specify conditions to find anomalous events.

Synthetic data included inside a use case perform a key role in it, as they provide the necessary data to successfully understand what the use case intends to demonstrate.