Skip to content

Commit 6baf5d6

Browse files
jpipkin1kimsauce
andauthored
DOCS-677 - Update the "Enterprise Audit - Cloud SIEM" article (#5052)
* DOCS-677 - Update the Enterprise Audit Cloud SIEM app article * Fix broken anchor links * Fix broken anchor link * Update docs/integrations/sumo-apps/cse.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/sumo-apps/cse.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/sumo-apps/cse.md Co-authored-by: Kim (Sumo Logic) <[email protected]> * Update docs/integrations/sumo-apps/cse.md Co-authored-by: Kim (Sumo Logic) <[email protected]> --------- Co-authored-by: Kim (Sumo Logic) <[email protected]>
1 parent 47f2e00 commit 6baf5d6

16 files changed

+182
-89
lines changed

blog-cse/2023/12-31.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -922,7 +922,7 @@ Some of the highlights of Insight Trainer include:
922922
* **Machine Learning/AI-Driven Analytics** - Insight Trainer leverages machine learning and AI to deliver outcome-based recommendations geared towards the reduction of false positive and non-actionable Insights without compromising the actual detection value or true positive Insights in Cloud SIEM.
923923
* **Easy Adoption** - The dashboard is available as an update to our already existing Enterprise Audit Cloud SIEM application and can be set up to run with no additional configuration or data science knowledge.
924924

925-
Periodic application of the recommended changes will improve the quality of Insights generated by Cloud SIEM. For more information about the Insight Trainer, see our detailed [online documentation](/docs/integrations/sumo-apps/cse/#insight-trainer).
925+
Periodic application of the recommended changes will improve the quality of Insights generated by Cloud SIEM. For more information about the Insight Trainer, see our detailed [online documentation](/docs/cse/rules/insight-trainer/).
926926

927927
#### Bug Fixes
928928

docs/cse/rules/insight-trainer.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ keywords:
1212
import useBaseUrl from '@docusaurus/useBaseUrl';
1313
import Iframe from 'react-iframe';
1414

15-
[Cloud SIEM - Insight Trainer](/docs/integrations/sumo-apps/cse#insight-trainer) is a dashboard in the Enterprise Audit - Cloud SIEM app. Insight Trainer offers suggestions for making adjustments to rules, such as writing rule tuning expressions and changing severities. Implementing the recommendations causes rules to be more effective at creating high-fidelity signals, resulting in generation of more meaningful insights.
15+
[Cloud SIEM - Insight Trainer](/docs/integrations/sumo-apps/cse/#cloud-siem---insight-trainer) is a dashboard in the Enterprise Audit - Cloud SIEM app. Insight Trainer offers suggestions for making adjustments to rules, such as writing rule tuning expressions and changing severities. Implementing the recommendations causes rules to be more effective at creating high-fidelity signals, resulting in generation of more meaningful insights.
1616

1717
:::sumo Micro Lesson
1818

@@ -66,7 +66,7 @@ The dashboard makes two kinds of suggestions, either a “tunability” score to
6666

6767
## Cloud SIEM - Insight Trainer page
6868

69-
After installing the [Enterprise Audit - Cloud SIEM app](/docs/integrations/sumo-apps/cse), access the [Cloud SIEM - Insight Trainer](/docs/integrations/sumo-apps/cse#insight-trainer) dashboard by clicking the [Library](/docs/get-started/library) icon in the left nav bar.
69+
After installing the [Enterprise Audit - Cloud SIEM app](/docs/integrations/sumo-apps/cse), access the [Cloud SIEM - Insight Trainer](/docs/integrations/sumo-apps/cse/#cloud-siem---insight-trainer) dashboard by clicking the [Library](/docs/get-started/library) icon in the left nav bar.
7070

7171
The dashboard has the following sections:
7272
* [Filters](#filters)

docs/cse/troubleshoot/troubleshoot-mappers.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@ For information about creating log mappers, see [Create a Structured Log Mapping
2121

2222
### Failed Records dashboard
2323

24-
The [Enterprise Audit - Cloud SIEM app](/docs/integrations/sumo-apps/cse/) provides dashboards and queries for greater visibility into Cloud SIEM activity. Troubleshooting parser failures is aided by the [Cloud SIEM - Record Analysis - Failed Records](/docs/integrations/sumo-apps/cse/#record-analysis-failed-records) dashboard and query found within the app. (The Enterprise Audit - Cloud SIEM app must be installed).
24+
The [Enterprise Audit - Cloud SIEM app](/docs/integrations/sumo-apps/cse/) provides dashboards and queries for greater visibility into Cloud SIEM activity. Troubleshooting parser failures is aided by the [Cloud SIEM - Record Analysis - Failed Records](/docs/integrations/sumo-apps/cse/#cloud-siem---record-analysis---failed-records) dashboard and query found within the app. (The Enterprise Audit - Cloud SIEM app must be installed).
2525

2626
Common failure types:
2727
* **Parser failures**. Include parser path and specific parsing error.

docs/cse/troubleshoot/troubleshoot-parsers.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -65,7 +65,7 @@ Following these fundamentals will help prevent common parsing issues and simplif
6565

6666
### Failed Records dashboard
6767

68-
The [Enterprise Audit - Cloud SIEM app](/docs/integrations/sumo-apps/cse/) provides dashboards and queries for greater visibility into Cloud SIEM activity. Troubleshooting parser failures is aided by the [Cloud SIEM - Record Analysis - Failed Records](/docs/integrations/sumo-apps/cse/#record-analysis-failed-records) dashboard and query found within the app. (The Enterprise Audit - Cloud SIEM app must be installed).
68+
The [Enterprise Audit - Cloud SIEM app](/docs/integrations/sumo-apps/cse/) provides dashboards and queries for greater visibility into Cloud SIEM activity. Troubleshooting parser failures is aided by the [Cloud SIEM - Record Analysis - Failed Records](/docs/integrations/sumo-apps/cse/#cloud-siem---record-analysis---failed-records) dashboard and query found within the app. (The Enterprise Audit - Cloud SIEM app must be installed).
6969

7070
Common failure types:
7171
* **Parser failures**. Include parser path and specific parsing error.

0 commit comments

Comments
 (0)