Analytics advisories

Prev Next

Analytics advisories are generated each time a detector determines that something on your network is behaving in an anomalous way. These advisories are events that can be used in searches.

Use class:analytics* in searches to view advisories.

Note

Advisories with the analytics_beta class name are in active development and may be more prone to false positives.

Analytics use the following scoring system to determine a severity rating:

  • 0: Informational

  • 14: Low

  • 57: Medium

  • 810: High

  • 11 and higher: Critical

All advisories contain the fields shown in the following table.

Field

Description

application

Name of the analytic detector.

description

Brief description of the analytic.

explanation

Details about what was found and how the advisory was scored.

score_detail

Summary of how the advisory was scored, with less detail than the explanation field.

score

Numeric score.

severity

Severity rating.