Analyst Manual¶
The Analyst Manual
Cybersecurity and data analysts use the Analyst Manual to:
- Query data
- Create cybersecurity detections
- Create data visualizations
- Create and customize parsing rules
- Use and create other analytical tools
To learn how to use the TeskaLabs LogMan.io web app, visit the User Manual. For information about setup and installation, see the Administration Manual and the Reference guide.
Quick start¶
- Queries: Writing queries to find and filter data
- Dashboards: Designing visualizations for data summaries and patterns
- Parsing rules: Creating and customizing parsing rules
- Detections: Creating custom detections for activity and patterns
- Lookups in detections: Whitelists, blacklists, and using lookups in correlation rules
- Geolocation lookups: Custom IP range zones
- Custom MaxMind enricher: Attach your own
.mmdband map attributes onto events - Threat intelligence feeds: Filling IOC lookups from feeds and wiring them into detections and risk scoring
- Advanced correlation rules: Multi stage detections in the library (Advanced and Sysmon window rules) and how to validate them in a lab
- Monitoring detection performance: Reading metrics on the Detections screen and tuning slow rules
- Notifications: Sending messages via email from detections or alerts