Filtering data in Enterprise Insights
Complete the following steps to navigate to Enterprise Insights view:
In the screen's upper right corner is the application menu icon . Click the icon to open the application dropdown menu. Select Enterprise Insights as shown in the following figure.
The Enterprise Insights view is displayed with IOC Domain Matches and Recent Alerts. You can adjust the time range using the slider to display a greater range of matches and alerts.
Enterprise Insights view
Click the icon in the top right corner of the Chronicle user interface. The Procedural Filtering menu opens as shown in the following figure. From Enterprise Insights, the Procedural Filtering menu enables you to further filter information pertaining to the current alerts and IOCs within your enterprise.
The following Procedural Filtering options are available from Enterprise Insights:
- ALERT NAME CATEGORIES
- ALERT VENDOR SOURCE
- IOC CATEGORIES
- IOC CONFIDENCE SCORE
- IOC FEED
- IOC/ALERT SEVERITY