Skip to main content
Version: 6.0

Malware

Description​

The Malware section is designed for monitoring events related to malware, particularly its detection and the elimination of infection threats.

Displayed Data​

  • Number of infected hosts / detected infections / blocked infections
  • Malware statistics by type
  • Dynamics of detected / blocked infections
  • Top detected / blocked malware
  • Top hosts by detected / blocked malware
  • Infection event statistics with details by hosts
  • Infection event statistics with details by malware

List of Dashboards​

  • Malware: Overview
  • Malware: Infected Host Profile
  • Malware: Malware Type Profile

Data Model​

The section uses the data source fields described below. Alias used: sm_cs_malware_indexes.

Categorization Fields​

Field NameValue
event.kindalert.
event.categorymalware.
event.actionFrom the source event.

General Purpose Fields​

Malware Detection Location host​

Field NameValue
host.ipIP address of the host where malware was detected.
host.nameName of the host where malware was detected.

User user​

Field NameValue
user.nameUsername.
user.domainUser domain.

Infection Source file​

Field NameValue
file.nameName of the file with malware.
file.pathFull path to the file with malware.
file.hashHash of the file with malware.

Other Fields​

Field NameValue
event.originalOriginal event text.

Optional Fields​

Field NameValue
messageEvent description.
malware_descriptionThreat description.

Dictionaries​

Below is a table of dictionaries used by the section.

NameFieldsDescription
sm_cs_malware_typemalware_description
malware_type
Dictionary of threat types.
sm_cs_malware_actionevent.action
malware_action - (detected | blocked)
Dictionary of actions with threats.

Example Sources​