Skip to main content
Version: 5.1

System Search Patterns

For proper operation of Search Anywhere Framework, there are several system search patterns responsible for storing information required by various modules. Manually creating indexes that match these search patterns is not recommended to maintain system stability.

JOB SCHEDULER

NameStored Information
.smos_metrics-*Results of active metric calculations in the Asset Service Model.
.smos_risk-*Results of active Risk Score Calculation actions.
.smos_mitre-*Results of active MITRE ATT&CK® Technique Recording actions.

INCIDENT MANAGER

NameStored Information
.smos_incidents*List of incidents created manually or via the Create Incident active action.
.sm_incident_aggregation_results*List of aggregation results.

RSM

NameStored Information
.sm_rsm_snapshot*List of Asset Service Model snapshots during execution.

RSMv2

NameStored Information
.sm_rsm_v2_calculated_metrics*Metric calculations.
.sm_rsm_v2_calculated_metric_entities*Object metric calculations.
.sm_rsm_v2_calculated_service_health*Service health calculations.

UBA

NameStored Information
.sm_uba_policies_statistics*UBA policy execution statistics.
.sm_uba_objects_statistics*UBA object execution statistics.
.sm_uba_objects_scoring*List of scoring objects.

INVENTORY

NameStored Information
.sm_inv_history_changes*Change history list.
.sm_inv_statistics*Asset calculation module execution statistics.