We are thrilled to announce a major enhancement to the Query Builder that now supports Alerts and Cases in public Beta
! This significant upgrade empowers users to create more complex and insightful dashboards, seamlessly integrating data beyond just events.
This feature is a game changer for SOC managers and analysts. With these new capabilities, users can visualize operational data in ways that were previously unattainable.
Imagine creating dynamic dashboards that can showcase:
From alerts
- Trends in alerts by creation date: Gain insights into unusual spikes in alert activity to proactively respond to potential threats.
- Alerts summary by status: Quickly understand the
current distribution of alerts, enabling better prioritization of
actions for effective incident management.
- Alerts by rule name: Evaluate the performance and effectiveness of alert-generating rules, allowing for fine-tuning of detection strategies.
- Average time to resolve alerts: Measure and improve performance by tracking the average time taken to resolve alerts, enhancing incident response efficiency.
From cases
- Trend of cases created over time: Analyze case creation patterns to identify peak times, helping correlate them with specific security events or incidents.
- Open cases by user or system creator: Recognize active contributors to incident reporting, enabling targeted feedback and support.
- Cases by community UUID: Assess case distribution across communities to identify localized security issues, facilitating tailored responses.
With these enhancements, the possibilities for data-driven decision-making are endless. Dive in, explore the new features, and start building dashboards that drive impactful security operations!
Happy querying! π
Documentation