SBN

How to Make the Most out of IncMan SOAR’s Search Bar: Step-By-Step Guide

At DFLabs, we always pride ourselves on our dedication to make IncMan SOAR as user-friendly as possible. Now, we’re going to show you in practice how we make that happen.

IncMan SOAR’s Incident Search Query Bar is easily configurable and allows users to customize their viewing perspective and choose which data they want to see. In the remainder of this blog, we will guide you through the process of using IncMan SOAR’s Search Query Bar swiftly and with ease through a visual and written presentation.

Let’s begin.

Using IncMan SOAR’s Search Query Bar

First and foremost, the incident section includes all incidents generated by IncMan SOAR, and clicking on any of the incident IDs will open the incident. Then, users can configure which incidents are displayed by creating queries against available incident data and saving them as incident filters.

Another way to manipulate what data is displayed from the incident section is by adjusting which columns are viewable. Users can adjust the columns by clicking on the cogwheel on the top-right side of the screen. 

This will display a configuration screen that allows users to choose which data is displayed on the screen and where it is displayed by clicking the “+” sign next to the selection and then dragging and dropping the selection. Once the columns are added and organized, click “Apply” to continue.

Furthermore, the search bar in the incident section has extensive capabilities to filter the incidents. From the Incident section, users can:

  • Search
  • Build
  • And issue queries against existing incidents

They can do that by simply typing in the search bar at the top of the screen.

IncMan SOAR also provides its users with a command cheat sheet to help build incident filtering queries. To access the cheat sheet, simply click on the info icon to display the query options.

Let’s say you want to review all incidents of a particular category with a certain status. By using a combination of logical words, we can perform simple and complex queries to see related data.

IncMan SOAR Search Bar

This allows us to perform filtering regarding all the entities that users would consider relevant throughout the investigation.

Often, we want to view incidents we are involved in. Searching for the keyword that involves “true,” or the keyword that involves “false” for the opposite scenario, we get a list of the incidents in which we are involved or the group we are a member of.

IncMan SOAR Search Bar

During the building of the search queries, there are three different ways of using them:

  • Search in a row
  • Exact match
  • Partial match

Difference between searching in a row, a certain value in a column (attribute), and an exact match

If users want to view incidents that contain a certain word anywhere in the row of the data of the incident, they can just type the word in the search bar. 

In the example below, the searched word is “phishing,” and regardless of whether the category differs from the searched one, it matches the word phishing in the short description attribute, and therefore shows the related incidents. 

IncMan SOAR Search Bar #3

If a user searches for the word phishing in the category column, the search should be performed with the use of the “:” sign.

IncMan SOAR Search Bar #4

Notice how only incidents that contain the word phishing in the Category column are displayed.

The last option is using an exact match which is performed with the “=” operator.

IncMan SOAR Search Bar #5

IncMan SOAR Search Bar #7

Notice how the exact match (use of the = operator) is case sensitive. 

Date and Time in Search queries

If you, for example, want the query to show a specific period, you can just enter the “AND” operator. 

Then, once again, use the field “Opening Time” to be equal to or less than a certain date. For instance, the 10th of September 2020, in the same principle as the first time. This will give you the following results. 

IncMan SOAR Search Bar #8

Additional info on using the queries

For additional information regarding the operators and how the queries can be composed, refer to the operators’ Helper section.

IncMan SOAR Search Bar #10

By selecting “Show more…” you can see additional information on how to write the queries.

IncMan SOAR Search Bar #11

Making IncMan SOAR user-friendly a top priority for DFLabs

Our goal is to make IncMan SOAR as more user friendly as possible. And as we continue to mold the shape of the next-gen IncMan SOAR, we prioritize user-friendliness as one of our most important objectives.

We always strive to enhance IncMan SOAR and align it with your current needs. This is why we listen to your feedback and will offer an even more user-friendly solution in our latest IncMan SOAR 5.3. version that is packed with a myriad of innovative features and improvements with just one goal – make life easier for you.

L’articolo How to Make the Most out of IncMan SOAR’s Search Bar: Step-By-Step Guide proviene da DFLabs.

*** This is a Security Bloggers Network syndicated blog from Our Blog – DFLabs authored by DFLabs. Read the original post at: https://www.dflabs.com/resources/blog/how-to-make-the-most-out-of-incman-soars-search-bar-step-by-step-guide/