Records, Signals, Entities, and Insights
Learn about insight generation, working with entities, and how to query Cloud SIEM records.Â
In this section, we'll introduce the following concepts:

Insight Generation Settings
Learn how to configure the detection window and the threshold activity score for insight generation.

Global Intelligence for Security Insights
Learn how to triage and prioritize insights.

Custom Insights
Learn how to set up custom insight configurations.

View and Manage Entities
Learn about all the entities in Cloud SIEM and their activity scores.

Entity Criticality
Learn how to adjust the severity of signals for specific entities.

Custom Entity Types
Learn how to create custom entity types in Cloud SIEM.

Entity Groups
Learn how to automatically group entities in terms of criteria like name or IP address.

Entity Lookup Tables
Learn how to normalize the names of users and hosts (machines) in your environment.

View Records for a Signal
Learn how to view records associated with a signal in Cloud SIEM.

Signal Suppression
Learn about ways to suppress and exclude Cloud SIEM signals from the insight generation process.

Search Sumo Logic for Cloud SIEM Records
Learn to search the Sumo Logic platform for records and signals that have been forwarded from Cloud SIEM.

Using Tags
Learn how to add context to Cloud SIEM items, and search and filter items by tag.