You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
| a | This area shows the total number of unique entities in Cloud SIEM. |
79
-
| b | In the **Filters** area, you can filter the list of entities by activity score, hostname, IP address, username, tags, type, and suppressed. |
80
-
| c | In this area you can sort entities by activity score, name, or type. |
81
-
| d | The Import Metadata option allows you to upload a .csv file of updates to entity tags, suppression state, and criticality, as described in [Update multiple entities](#update-multiple-entities). |
82
-
| e | Shows the entity type and its value. |
83
-
| f | If an entity has the **Suppressed** indicator, that means that signals will not be fired on the entity. |
84
-
| g | The **Criticality** column shows whether a [criticality](/docs/cse/records-signals-entities-insights/entity-criticality/) has been assigned to the entity. A criticality adjusts the severity of signals for specific entities based on some risk factor or other consideration. If a criticality hasn't been assigned to an entity, the column contains "default". |
85
-
| h | The current activity score for the entity, which by default is the sum of the severities of the signals that have fired on the entity over the previous two weeks. For more information, see [Understanding entity activity scores](/docs/cse/get-started-with-cloud-siem/insight-generation-process#understanding-entity-activity-scores), in the *Insight Generation Process* topic. |
86
-
| i | The total amount of signal severity for the entity. |
87
-
88
-
If you see a link below the entity value, it’s a [tag](/docs/cse/records-signals-entities-insights/tags-insights-signals-entities-rules/). You can click it to filter entities by that tag.
77
+
| a |**Filters**. Filter the list of entities by values such as signal severity total, activity score, criticality, indicator, sensor zone, suppressed, tags, type, and value. |
78
+
| b |**Import Metadata**. Upload a .csv file of updates to entity tags, suppression state, and criticality, as described in [Update multiple entities](#update-multiple-entities). |
79
+
| c | **Checkboxes**. Select checkboxes to [update multiple entities](#update-multiple-entities).
80
+
| d |**Entity**. Displays the entity name. |
81
+
| e |**Entity Type**. Shows the entity type and its value. |
82
+
| f |**Activity Score**. The current activity score for the entity, which by default is the sum of the severities of the signals that have fired on the entity over the previous two weeks. For more information, see [Understanding entity activity scores](/docs/cse/get-started-with-cloud-siem/insight-generation-process#understanding-entity-activity-scores), in the *Insight Generation Process* topic. |
83
+
| g |**Signal Severity Total**. The total amount of signal severity for the entity. |
84
+
| h |**Suppressed Lists**. If an entity is on a suppressed list, that means that signals will not be fired on the entity. |
85
+
| i |**Criticality**. Shows whether a [criticality](/docs/cse/records-signals-entities-insights/entity-criticality/) has been assigned to the entity. A criticality adjusts the severity of signals for specific entities based on some risk factor or other consideration. If a criticality hasn't been assigned to an entity, the column contains "default". |
89
86
90
87
## About the entities details page
91
88
@@ -149,17 +146,15 @@ or criticality for one or more entities.
149
146
### Update entities from the UI
150
147
151
148
1.[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). Click **Entities** at the top of the screen. <br/>[**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Cloud SIEM > Entities**. You can also click the **Go To...** menu at the top of the screen and select **Entities**.
152
-
1. Note that there is a checkbox at the left end of each entity row, and one above the entities list. <br/><img src={useBaseUrl('img/cse/entities-page.png')} alt="Entities page" style={{border: '1px solid gray'}} width="800"/>
153
-
1. Click the top checkbox to select all of the entities on the page, or click the checkbox next to each entity you want to update.
154
-
1. Note that once you select an entity, three options appear at the top of the entities list. <br/><img src={useBaseUrl('img/cse/update-options.png')} alt="Update options" style={{border: '1px solid gray'}} width="800"/>
155
-
<br/>See the instructions for each option below:
156
-
*[Update tags](#update-tags)
157
-
*[Update suppression](#update-suppression)
158
-
*[Update criticality](#update-criticality)
149
+
1. Note that there is a checkbox at the left of each entity row, and one above the entities list. Click the top checkbox to select all of the entities on the page, or click the checkbox next to each entity you want to update.
150
+
1. Note that once you select checkboxes for multiple entities, a box slides out showing three options above the list of selected entities. See the instructions for each option below:
1. After selecting the entities you want to update, click **Update Tags**.
157
+
1. After selecting the entities you want to update, click **Change Tags**.
163
158
1. Click the down arrow to display the options: <br/><img src={useBaseUrl('img/cse/tag-options.png')} alt="Tag options" style={{border: '1px solid gray'}} width="400"/>
164
159
***Add.** Select this option to add one or more tags to the entity, without affecting any tags already assigned to the entity. You’re prompted to select a tag. If you select a schema tag, you’re prompted to select a tag value. You can select multiple tags to add.
165
160
***Remove**. Select his option to remove one or more tags from the entity. You’re prompted to select a tag. If you select a schema tag, you’re prompted to select a tag value. You can select multiple tags to remove. If a selected entity doesn't have the specified tags, no change will be made to the entity.
@@ -168,19 +163,17 @@ or criticality for one or more entities.
168
163
When you use the **Replace** option, be sure to specify new tags. If you do not, the existing tags will still be removed.
169
164
:::
170
165
1. As you select tags, they’ll appear in the update popup. <br/><img src={useBaseUrl('img/cse/tags-to-add.png')} alt="Add tags to entities" style={{border: '1px solid gray'}} width="400"/>
171
-
1. When you are done selecting tags, click **Update Entity Tags**.
166
+
1. When you are done selecting tags, click **Confirm**.
172
167
173
-
#### Update suppression
168
+
#### Change suppression
174
169
175
-
1. After selecting the entities you want to update, click **Update Suppression**.
176
-
1. The **Update Suppression** popup appears, with the suppression toggle set to **Not Suppressed**. <br/><img src={useBaseUrl('img/cse/before-suppression.png')} alt="Update suppression" style={{border: '1px solid gray'}} width="400"/>
177
-
1. If you want to unsuppress the selected entities, click **Update Entity Suppression**. Otherwise, if you want to suppress the entity, toggle the slider to **Suppressed**, supply a comment if desired, and then click **Update Entity Suppression**.
170
+
1. After selecting the entities you want to update, click **Change Suppression**. A popup appears, with the suppression toggle set to **Don't Suppress**. <br/><img src={useBaseUrl('img/cse/before-suppression.png')} alt="Update suppression" style={{border: '1px solid gray'}} width="400"/>
171
+
1. If you want to suppress the entities, toggle the slider to **Suppress**, supply a comment if desired, and then click **Confirm**.
178
172
179
-
#### Update criticality
173
+
#### Change criticality
180
174
181
-
1. After selecting the entities you want to update, click **Update Criticality**.
1. If you want to assign default criticality to the selected entities, click **Update Entity Criticality**. Otherwise, use the down arrow to view defined Criticalities, select one, and then click **Update Entity Criticality**.
175
+
1. After selecting the entities you want to update, click **Change Criticality**. The **Change Criticality** popup appears. <br/><img src={useBaseUrl('img/cse/update-criticalities.png')} alt="Update criticalities" style={{border: '1px solid gray'}} width="400"/>
176
+
1. If you want to assign default criticality to the selected entities, click **Confirm**. Otherwise, use the down arrow to view defined criticalities, select one, and then click **Confirm**.
0 commit comments