Viewing information about an IOA rule

To view information about an IOA rule:

  1. In the program web interface window, select the IOC/IOA Analysis section, IOA Analysis subsection.

    The table of IOA rules opens.

  2. Select the IOA rule whose information you want to view.

This opens a window containing information about the IOA rule.

The window contains the following information:

The Details tab shows the following information:

The Query tab displays the source code of the query being checked. By clicking the link with the text of the query you can navigate to the Threat Hunting section and view all events matching the given search criteria.

See also

Viewing the IOA rule table

Enabling or disabling an IOA rule

Adding an IOA rule

Editing an IOA rule

Deleting an IOA rule

Viewing an IOA white list

Viewing information about an IOA rule in the white list

Adding an IOA rule to the white list

Removing an IOA rule from the white list

Viewing the IOA analysis results

Filtering and searching IOA rules

Clearing an IOA rules filter

Page top