Security Compliance

Search IsThreat TCPTrafficAudit Events in SEM HTML5 Console

This article describes how to perform "IsThreat" event search in SEM's (Security Event Manager (formerly Log & Event Manager) HTML5 console under the Analyze Historical Data tab

First published date

11/1/2020 8:37 PM

Last published date

11/1/2020 8:37 PM

Overview

This article provides steps on how to perform search for "IsThreat" events in the new HTML5 console under the Analyze Historical Data tab in SEM's (Security Event Manager (formerly Log & Event Manager). 
Analyze Historical data tab is only available from SEM 2019.4 on-wards.

Product section

Security Event Manager

Cause

NA

Resolution

As "IsThreat" status is a correlation filed condition under the TCPTRafficAudit Event, you can use below sample query in "Analyze historical data in SEM" and filter or search all the events based on the SourceMachine Address. To Narrow down your search results, you can modify this query further more by adding additional correlation conditions. 

Sample Query: TCPTrafficAudit.IsThreat = true AND TCPTrafficAudit.SourceMachine = "123.123.123.123"

To know more about these events check out Using the Threat Intelligence feed in SEM

Image_2020-10-30_09-37-30.png