Analytics advisories are generated each time a detector determines that something on your network is behaving in an anomalous way. These advisories are events that can be used in searches.
Use class:analytics* in searches to view advisories.
Note
Advisories with the
analytics_betaclass name are in active development and may be more prone to false positives.
Analytics use the following scoring system to determine a severity rating:
0: Informational
1–4: Low
5–7: Medium
8–10: High
11 and higher: Critical
All advisories contain the fields shown in the following table.
Field | Description |
|---|---|
application | Name of the analytic detector. |
description | Brief description of the analytic. |
explanation | Details about what was found and how the advisory was scored. |
score_detail | Summary of how the advisory was scored, with less detail than the explanation field. |
score | Numeric score. |
severity | Severity rating. |