- Get Started with Outcomes Navigator
- Use Outcomes Navigator from a MITRE ATT&CK® Perspective
- Use Outcomes Navigator from a Threat Detection, Investigation, and Response (TDIR) Use Case Categories Perspective
- View Recommendations for Improving Your Configuration
- Share Information in Outcomes Navigator
- Outcomes Navigator Coverage Calculation
- Outcomes Navigator Parser Calibration Tier Average Calculation
Use Case Coverage Score
Quickly understand the efficacy of your configuration in protecting against Exabeam use cases.
The Use Case Coverage Score is a metric of how well your environment is configured to protect against use cases, also known as your environment's coverage. At a glance, you can summarize the strength of your protection without analyzing the numbers and details yourself.
The Use Case Coverage Score may describe all use cases or a specific use case.
Overall Use Case Coverage Score
The overall Use Case Coverage Score is a metric of how well your environment is configured to protect against all use cases across the board.
The score is determined by the average Use Case Coverage Score across all unhidden use cases.
Best – The average Use Case Coverage Score across all unhidden use cases is 75 to 100.
Better – The average Use Case Coverage Score across all unhidden use cases is 50 to 74.
Good – The average Use Case Coverage Score across all unhidden use cases is one to 49.
None – Your environment wasn't able to calculate an overall Use Case Coverage Score.
The average is calculated by:
where A is the average, S is the sum of all Use Case Coverage Scores across all unhidden use cases, and N is the total number of all unhidden use cases.
The overall Use Case Coverage Score is calculated once per day.
You can view your overall Use Case Coverage Score, when it was last calculated, and a chart depicting trends in the score over a one-month, three-month, or six-month period in a summary of your use case coverage.
If the chart depicts the overall Use Case Coverage Score over a one-month period, each bar represents the average overall Use Case Coverage Score for a given a week. This average is calculated by:
where A is the average Use Case Coverage Score for a given week, S is the sum of daily overall Use Case Coverage Scores calculated in the week, and N is the number of times the daily overall Use Case Coverage Score has been calculated in a given week.
If the chart depicts the overall Use Case Coverage Score over a three-month or six-month period, each bar represents the average overall Use Case Coverage Score for a given month. This average is calculated by:
where A is the average Use Case Coverage Score for a given month, S is the sum of weekly overall Use Case Coverage Scores calculated in the month, and N is the number of times the weekly overall Use Case Coverage Score has been calculated in a given month.
Use Case Coverage Score for a Specific Use Case
The Use Case Coverage Score for a specific use case is a metric of how well your environment as a whole is configured to protect against a specific use case.
The score aggregates the coverage levels of all Exabeam applications or features Outcomes Navigator assesses, including Advanced Analytics rules, correlation rules, analytics rules, and Dashboards. Your score for a given use case is determined by the percentage of possible parsed fields across all Exabeam applications or features that your environment actively parses:
Best – Your environment actively parses 75 to 100 percent of all possible parsed fields relevant to the use case.
Better – Your environment actively parses 50 to 74 percent of all possible parsed fields relevant to the use case.
Good – Your environment actively parses one to 49 percent of all possible fields relevant to the use case.
None – Your environment doesn't parse any fields relevant to the use case.
To determine the fields your environment actively parses across all Exabeam applications or features for a given use case, Outcomes Navigator takes the union of all possible parsed fields across Exabeam applications or features and compares it to the fields your environment actively parses for the use case.
The percentage is calculated by:
where P is the percentage, AF is the number of fields your environment actively parses across all Exabeam applications or features for the use case, and TF is the number of fields in the union of all possible parsed fields across Exabeam applications or features for the use case.
Because the Use Case Coverage Score is based on the amount and quality of data, the best way to improve your score is to configure a wider variety of relevant products and ensure the values in the logs from those products are fully extracted. Follow recommendations to improve your Use Case Coverage Score directly in Outcomes Navigator. You can view recommendations only if you have a license that includes Advanced Analytics.