Synthetic data: Palo Alto threat injection
Purpose
The Palo Alto threat injection is a one-shot injection of the tables firewall.paloalto.threat
learn more and firewall.all.traffic
learn more. The events of the file are sent at a frequency of 1 second.
Open synthetic data
Once the synthetic data has been launched, you can use the Open button at the top right of the card in Exchange to access the search window, where you can check the data table with the synthetic data. You can also access the data table using finders or LINQ via the Navigation pane (Data Search area → Explore your data tab).
Use synthetic data
After launching the synthetic data, you can use it in various contexts, such as the search window to perform operations to analyze the data, Activeboards to visualize and analyze the data graphically, or alerts to specify conditions to find anomalous events.
Â