Create a query to find malware events per subnet best practice

Prev Next

Create a query to find malware events and sort them by subnet. This query helps you find networks in your environment that are under attack.

For details about product features, usage, and best practices, click ? or Help.

  1. To duplicate the existing Threat Event Descriptions in the Last 24 Hours query, select MenuReportsQueries & Reports, then find and select the Threat Target IP Address query in the list.

  2. Click ActionsDuplicate and in the Duplicate dialog box, edit the name, select the group to receive the copy, then click OK.

  3. In the Queries list, find the new query that you created and click Edit.

    The duplicated query is displayed in the Query Builder with the Chart tab selected.

  4. In the Display Results As list, select Table under List.

  5. In the Configure Chart: Table dialog box, select Threat Target IPv4 Address from the sort by list and Value (Descending), then click Next.

  6. In the Columns tab, you can use the preselected columns.

    Tip

    It might help to move the Threat Target IPv4 Address closer to the left of the table, then click Next.

    Don't change the default Filter tab settings.

  7. Click the Summary tab, confirm that the query settings are correct, then click Save.

  8. In the Queries list, find the query that you created, then click Run.

Now you have a query to find malware events and sort them by IP subnet address.