Skip to main content

Investigate

Data analysis creates the notifications and, in turn, the aggregated cases. This section starts at what happens after a case is created: how an analyst reviews it, works down from the summary into the underlying events, and closes the loop by tuning the rule that fired.

Three (3) Tier Operations

The review workflow

  1. Overview Summary — the queue of behavior-summary tickets (below).
  2. Behavior Summary (case) — pre-defined investigations and case status/ticketing.
  3. Behavior Timeline — the chronological event view for the entity.
  4. Investigation — event searching in the Data Lake.
note

In the current interface these pages are found under the SIEM menu (Overview Summary, Behavior Summary, Behavior Timeline) and the Data Lake menu (Search). Flow searching, from the older interface's Network Flows page, is no longer a separate step. See Page Functionality for the current pages.

Overview Summary

Choose the Overview Summary option under the SIEM menu in the navigation bar (/SIEM/overviewSummary). The page is subtitled Overview of Fluency Behavior Summaries.

Overview Summary page with three ticket counter cards, time-range buttons, severity and status filters, and the records list

The three counter cards at the top — Total Tickets (all tickets generated in the period), Tickets Closed By AI (tickets resolved automatically, marked with a circled-x icon), and Open Tickets (tickets still awaiting review, marked with a warning-triangle icon) — summarize the behavior-summary tickets listed in the Records section below, for the selected time range.

The time range is set by the button group in the upper right: 1D (the default), 3D, 7D, 30D, 90D, and ALL TIME, with a calendar icon beside ALL TIME for a Custom date range.

Two controls sit between the counters and the records list: a Show 0 score events checkbox, off by default, which includes zero-score events in the list when enabled, and a Severity Filter dropdown.

Severity Filter dropdown open, showing Select All plus Critical, High, Serious, Medium, and Low checkboxes

The Severity Filter dropdown holds a Select All checkbox — checked by default, so every severity is included — followed by one checkbox per level: Critical, High, Serious, Medium, and Low.

The Records list itself is filtered by ticket status with the tab bar on its right: All (the default), New, Acknowledged, Closed, and Closed By AI. When nothing matches, the list shows No records found; the footer bar reports the visible range and pages through longer lists.

To see how this table is dug into, continue to Investigating a Behavior Alert.

In this section