Viewing the IOA analysis results

To find and view IOA analysis results for user-defined rules:

  1. In the program web interface window, select the IOC/IOA Analysis section, IOA Analysis subsection.

    The table of IOA rules opens.

  2. Select the IOA rule for which you want to view scan results.

    This opens a window containing information about the IOA rule.

  3. Do one of the following:
    • If you want to view alerts generated by the IOA rule, click Alerts to proceed to the alerts database.

      The alert table is opened in an new browser tab.

    • If you want to view events generated by the IOA rule, click Events to proceed to the events database.

      The event table is opened in an new browser tab.

To find and view IOA analysis results for Kaspersky Lab rules:

  1. Select the Alerts section in the window of the program web interface.

    The table of alerts opens.

  2. Click the link in the Technologies column to open the filter configuration window.
  3. In the drop-down list on the left, select Contains.
  4. In the drop-down list on the right, select (IOA) IOA Analysis.
  5. Click the Apply button.

    The table displays alerts generated by IOA rules.

  6. Select an alert for which the Detected column shows the name of the relevant IOA rule.

    This opens a window containing information about the alert.

  7. Under Scan results, click the link with the name of the rule to open the rule information window.
  8. Do one of the following:
    • If you want to view alerts generated by the IOA rule, click Alerts to proceed to the alerts database.

      The alert table is opened in an new browser tab.

    • If you want to view events generated by the IOA rule, click Events to proceed to the events database.

      The event table is opened in an new browser tab.

See also

Viewing the IOA rule table

Viewing information about an IOA rule

Enabling or disabling an IOA rule

Adding an IOA rule

Editing an IOA rule

Deleting an IOA rule

Viewing an IOA white list

Viewing information about an IOA rule in the white list

Adding an IOA rule to the white list

Removing an IOA rule from the white list

Filtering and searching IOA rules

Clearing an IOA rules filter

Page top