Filtering data in Enterprise Insights

Complete the following steps to navigate to Enterprise Insights view:

  1. In the screen's upper right corner is the application menu icon Application menu icon. Click the icon to open the application dropdown menu. Select Enterprise Insights as shown in the following figure.

    Application menu on landing page Application menu

  2. The Enterprise Insights view is displayed with IOC Domain Matches and Recent Alerts. You can adjust the time range using the slider to display a greater range of matches and alerts.

    Enterprise Insights View Enterprise Insights view

  3. Click the Filtering Icon icon in the top right corner of the Chronicle user interface. The Procedural Filtering menu opens as shown in the following figure. From Enterprise Insights, the Procedural Filtering menu enables you to further filter information pertaining to the current alerts and IOCs within your enterprise.

    image Filtering options

    The following Procedural Filtering options are available from Enterprise Insights:

    • ALERT NAME CATEGORIES
    • ALERT VENDOR SOURCE
    • IOC CATEGORIES
    • IOC CONFIDENCE SCORE
    • IOC FEED
    • IOC/ALERT SEVERITY
    • TLD