Skip to main content
Version: 6.0

Intrusion

Description​

The Intrusion section is designed for monitoring threats and their sources and targets.

Displayed Data​

  • Number of unique source IP addresses of threats
  • Number of unique target IP addresses of threats
  • Total number of unique addresses
  • Threat statistics by type
  • Statistics by user agents
  • Number of events by source
  • Threat dynamics
  • TOP-10 sources of threats by number of intrusion attempts
  • TOP-10 targets of threats by number of intrusion attempts

List of Dashboards​

  • Intrusion Detection: Overview
  • Intrusion Detection: Threat Source Profile
  • Intrusion Detection: Threat Destination Profile

Data Model​

The section uses the data source fields described below. Alias used: sm_cs_threat_indeces.

Categorization Fields​

Categorization fields are not used by this section.

General Purpose Fields​

Observer observer​

Field NameValueUsage in Dashboards
observer.vendorInformation about the manufacturer of the intrusion detection system or network equipment that generated the event.Allows users to identify which system generates the most events.

Source source​

Field NameValueUsage in Dashboards
source.ipIP address of the threat source.Used to count the number of unique attackers aggs count by source.ip. Used as a link to the source profile from table rows.
source.addressThe physical or logical address of the source.Displayed in the target details table.
source.portThe source port.Displayed in the targets table (column name: Source Port).

Destination destination​

Field NameValueUsage in Dashboards
destination.ipIP address of the authentication destination.Primary filter $dest_ip$. Used to select a specific node for event analysis.
destination.portThe target port.Displayed in the Target Information table (column name: Target Port).

Threat Type rule​

Field NameValueUsage in Dashboards
rule.categoryType of threat source/target.Used in pie charts and bar graphs to analyze the distribution of threat types.

Agent ID user_agent​

Field NameValueUsage in Dashboards
user_agent.nameThe user agent information.Used in visualizations.

Dictionaries​

Dictionaries are not used by this section.

Example Sources​