Skip to main content
Version: 5.2

Intrusion

Description

The Intrusion section is designed for monitoring threats and their sources and targets.

Displayed Data

  • Number of unique source IP addresses of threats
  • Number of unique target IP addresses of threats
  • Total number of unique addresses
  • Threat statistics by type
  • Statistics by user agents
  • Number of events by source
  • Threat dynamics
  • TOP-10 sources of threats by number of intrusion attempts
  • TOP-10 targets of threats by number of intrusion attempts

List of Dashboards

  • Intrusion Detection: Overview
  • Intrusion Detection: Threat Source Profile
  • Intrusion Detection: Threat Destination Profile

Data Model

The section uses the data source fields described below. Alias used: sm_cs_threat_indeces.

Categorization Fields

Categorization fields are not used by this section.

General Purpose Fields

Observer observer

Field NameValueUsage in Dashboards
observer.vendorInformation about the manufacturer of the intrusion detection system or network equipment that generated the event.Allows users to identify which system generates the most events.

Source source

Field NameValueUsage in Dashboards
source.ipIP address of the threat source.Used to count the number of unique attackers aggs count by source.ip. Used as a link to the source profile from table rows.
source.addressThe physical or logical address of the source.Displayed in the target details table.
source.portThe source port.Displayed in the targets table (column name: Source Port).

Destination destination

Field NameValueUsage in Dashboards
destination.ipIP address of the authentication destination.Primary filter $dest_ip$. Used to select a specific node for event analysis.
destination.portThe target port.Displayed in the Target Information table (column name: Target Port).

Threat Type rule

Field NameValueUsage in Dashboards
rule.categoryType of threat source/target.Used in pie charts and bar graphs to analyze the distribution of threat types.

Agent ID user_agent

Field NameValueUsage in Dashboards
user_agent.nameThe user agent information.Used in visualizations.

Dictionaries

Dictionaries are not used by this section.

Example Sources