How to use "name-of-threatid" for threat types like "spyware"

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

How to use "name-of-threatid" for threat types like "spyware"

L2 Linker

Hello,

I want to filter Panorama Monitoring results based on the field "name-of-threatid" for threat types like "Spyware". But when I click on of the results, I get a filter like this: "... and ( name-of-threatid eq 'Grayware:ZZZZZ.com' )" but when I want to apply this filter I get this error:

Arman_Zaheri_0-1705929625551.png


It seems this field only accepts numbers. Do you have any idea what should I do about this?

 

Thank you

1 accepted solution

Accepted Solutions

L0 Member

Add column of 'ID' for the monitor threat logs and then use that spyware ID to filter on.

exa.

'Microsoft Windows NTLMSSP Detection'  = ( threatid eq '92322' )

-wherever you go, there you are-

View solution in original post

2 REPLIES 2

L0 Member

Add column of 'ID' for the monitor threat logs and then use that spyware ID to filter on.

exa.

'Microsoft Windows NTLMSSP Detection'  = ( threatid eq '92322' )

-wherever you go, there you are-

L2 Linker

And just a note! This problem is only in Panorama, in Cortex Data Lake it works like a charm!

  • 1 accepted solution
  • 2543 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!