Run a Sightings Search
Determine the prevalence of a threat over time or test remediation or eradication efforts. You can select individual or multiple observables and the date range for your search from a security incident. Results are included in the Security Incident Observables related list.
始める前に
Role required: sn_si.analyst
このタスクについて
注:
An active implementation must be configured. Sightings Search supports Elasticsearch, Splunk, McAfee ESM, HPE ArcSight Logger, and QRadar incident
enrichment. If no implementations are available, capability actions, such as Run Sightings Search, are not displayed in product menus.