Skip to main content
Version: 5.0

Malware

Description

The Malware section is designed for monitoring events related to malware, particularly its detection and the elimination of infection threats.

Displayed Data

  • Number of infected hosts / detected infections / blocked infections
  • Malware statistics by type
  • Dynamics of detected / blocked infections
  • Top detected / blocked malware
  • Top hosts by detected / blocked malware
  • Infection event statistics with details by hosts
  • Infection event statistics with details by malware

List of Dashboards

  • Malware: Overview
  • Malware: Infected Host Profile
  • Malware: Malware Type Profile

Data Model

The section uses the data source fields described below. Alias used: sm_cs_malware_indexes.

Categorization Fields

Field NameValue
event.kindalert
event.categorymalware
event.actionFrom the source event.

General Purpose Fields

Malware Detection Location host

Field NameValue
host.ipIP address of the host where malware was detected.
host.nameName of the host where malware was detected.

User user

Field NameValue
user.nameUsername.
user.domainUser domain.

Infection Source file

Field NameValue
file.nameName of the file with malware.
file.pathFull path to the file with malware.
file.hashHash of the file with malware.

Other Fields

Field NameValue
event.originalOriginal event text.

Optional Fields

Field NameValue
messageEvent description.
malware_descriptionThreat description.

Dictionaries

Below is a table of dictionaries used by the section.

NameFieldsDescription
sm_cs_malware_typemalware_description
malware_type
Dictionary of threat types.
sm_cs_malware_actionevent.action
malware_action - (detected | blocked)
Dictionary of actions with threats.

Example Sources