- Get Started with Threat Detection Management
- Analytics Rules
- Analytics Rule Classifications
- Create an Analytics Rule
- 1. Define the analytics rule
- 2. Import the analytics rule
- 3. Enable the analytics rule
- 4. Apply the analytics rule to your environment
- factFeature Analytics Rule JSON Configuration
- profiledFeature Analytics Rule JSON Configurationh
- contextFeature Analytics Rule JSON Configuration
- numericCountProfiledFeature Analytics Rule JSON Configuration
- numericDistinctCountProfiledFeature Analytics Rule JSON Configuration
- numericSumProfiledFeature Analytics Rule JSON Configuration
- Manage Analytics Rules
- Tune Analytics Rules
- Share Analytics Rules
- Troubleshoot Analytics Rules
- Analytics Rules Syntax
- Advanced Analytics Rule Syntax vs. Analytics Rule Syntax
- Logical Expressions in Analytics Rule Syntax
- String Operations Using Analytics Rule Syntax
- Integer Operations Using Analytics Rule Syntax
- Time Operations Using Analytics Rule Syntax
- Network Operations Using Analytics Rule Syntax
- Context Operations Using Analytics Rule Syntax
- Entity Operations Using Analytics Rule Syntax
- Correlation Rule Operations Using Analytics Rule Syntax
- Monitor the Analytics Engine
- Correlation Rules
- Threat Scoring
Network Operations Using Analytics Rule Syntax
Evaluate IP addresses, hosts, and domains using analytics rule syntax.
IP Address Operations
Evaluate IP addresses in your network.
Function | Description | Returned Value | Examples |
---|---|---|---|
| Checks if | Boolean |
|
| Checks if | Boolean |
|
| Checks if | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if An alternative form of | Boolean |
|
| Checks if the event contains geo-information Valid arguments for
| Boolean |
|
| Retrieves geo-information Valid arguments for
| String |
|
Client and Host Operations
Evaluate clients and hosts in your network.
Function | Description | Returned Value | Examples |
---|---|---|---|
| COMING SOON | Boolean | COMING SOON |
| Extracts the operating system from user agent | String |
|
| Extracts the browser from user agent | String |
|
Web Domain Operations
Evaluate web domains.
Function | Description | Returned Value | Examples |
---|---|---|---|
| Checks if domain
| Boolean |
|
| Retrieves a list of all threats associated with domain | String | returns COMING SOON |
| Extracts the domain from | String |
|
| Extracts the domain from | String |
|