Skip to main content

Demo Incident

Describes an older version of the product

The screenshots in this walkthrough are from an older version of the interface. The pages used are found in the current interface under the SIEM menu (Behavior Rules, Behavior Summary) and the Data Lake menu (Search) — see Page Functionality. The steps need to be re-verified against the current product.

Fluency EventWatch Rule

An EventWatch (behavior) rule is defined in Fluency.

Sign in to your Fluency portal at https://<companyname>.app.ingext.io — see Fluency Web Interface for the URL formats.

Choose the Behavior Rules option under the SIEM menu in the navigation bar.

Behavior rules are shown as below:

Behavior Rules page under the SIEM menu, listing the configured rules

For example, type "SyslogEventReceived" in the search bar and then you can see the result:

Behavior Rules filtered to the SyslogEventReceived rule

Syslog Test Event

A test event is injected into the system.

Choose the Search option under the Data Lake menu in the navigation bar.

Type "@Behaviors:"SyslogEventReceived"" in the search bar hen you can see the corresponding test event as below:

Events Search query bar with the @Behaviors:&quot;SyslogEventReceived&quot; search entered

Events Search results showing the injected test event

Behavior Alert

Fluency

A New alert is generated in Fluency for the above event.

Choose the Behavior Summary option under the SIEM menu in the navigation bar.

In the search bar on the left, type in "SyslogEventReceived" and the behavior alert is shown.

Behavior Summary filtered to SyslogEventReceived, showing the New alert

PagerDuty

An corresponding alert is sent to PagerDuty for the same incident.

Corresponding incident raised in PagerDuty for the same event

Resolution

Resolving the Alert in PagerDuty provide a real-time update back to Fluency.

PagerDuty incident marked as resolved

The alert now carries the Resolved status.

Fluency behavior alert now carrying the Resolved status