Skip to main content

Records, Signals, Entities, and Insights

Learn about Insight generation, working with Entities, and how to query Cloud SIEM Records. 

In this section, we'll introduce the following concepts:

icon

Insight Generation Settings

Learn how to configure the detection window and the threshold Activity Score for Insight generation.

icon

Global Intelligence for Security Insights

Learn how to triage and prioritize Insights.

icon

Custom Insights

Learn how to set up Custom Insight configurations.

icon

View and Manage Entities

Learn about all the Entities in Cloud SIEM and their Activity Scores.

icon

Entity Criticality

Learn how to adjust the severity of Signals for specific Entities.

icon

Custom Entity Types

Learn how to create custom Entity types in Cloud SIEM.

icon

Entity Groups

Learn how to automatically group entities in terms of criteria like name or IP Address.

icon

Entity Lookup Tables

Learn how to normalize the names of users and hosts (machines) in your environment.

icon

View Records for a Signal

Learn how to view Records associated with a Signal in Cloud SIEM.

icon

Signal Suppression

Learn about ways to suppress and exclude Cloud SIEM Signals from the Insight generation process.

icon

Search Sumo Logic for Cloud SIEM Records

Learn to search the Sumo Logic platform for Records and Signals that have been forwarded from Cloud SIEM.

icon

Using Tags

Learn how to add context to Cloud SIEM items, and search and filter items by tag.

Status
Legal
Privacy Statement
Terms of Use

Copyright © 2024 by Sumo Logic, Inc.