Classifiers


Overview

Classifiers Overview

Classifiers are used to manipulate, or preprocess, events before they get to the UI. For example, you can raise or lower the severity of an event, choose to ignore specific events from ThreatMatch, PatternScout, asset detection, or even drop an event before it reaches the GRID.  To be safe and not miss critical data, we recommend sending all data to the GRID.

Classifiers allow you to modify events or change how they're treated by the GRID. 

  • Exclude: No alerts. Data is still saved and searchable.
  • Change attributes: Alter how data is displayed, to make data more useful. 
  • Drop Events:  Discarded before they get to the GRID.  Be careful, it is not searchable or logged.  WARNING: Dropping events means that the event is not logged within the GRID. It is not searchable and does not trigger alerts.


Rules

Patterns and Rules 

When creating a Key / Value pair the field to apply an attribute to an event, the values in those fields are considered text. However, there are exceptions which are governed by the rules in the table below:

Match TypeEvent  FieldEvent TypeNotes
Patterns*timestampdate
geo_*
don't use this (reserved for custom geo-ip objects)
*_scorenumber (double)
*_portnumber (long)
bytes*number (long)
*_countnumber (long)
Exact Matchpraesidio_skip_adbooleanUse this to skip anomaly detection
cpu_utilizationnumber (double)
disk_io_utilizationnumber (double)
durationnumber (double)
load_avg_utilizationnumber (double)
memory_utilizationnumber (double)
scorenumber (double)
dropped_eventsnumber (long)
portnumber (long)
praesidio_parse_nanosnumber (long)
processed_eventsnumber (long)
stored_eventsnumber (long)
time_totalnumber (long)


Create

Creating a classifier 

Classifiers have a large impact on the functionality and efficiency of the GRID. Follow the instructions below to ensure your classifiers are syntactically correct and function properly. 

  1. Events > enter search query. All events matching the query display.
  2. Select the Classifier icon to create a classifier of your query.
  3. Fill in Classifier fields.
    1. Tag Name: Classifiers should have meaningful, easily identifiable names.
    2. Query String: [Auto-populated from the event search] Conditions the classifier is set to search on.
    3. Drop Event:  Warning: If drop event is checked, it does not log the event.  Events that match this classifier are not searchable and do not trigger alerts. (Be careful using this!)
    4. Exclude from ThreatMatch, PatternScout, or Asset Detection: Stop the system from using the event for threat intelligence, anomaly detection, or asset detection, respectively.
    5. Attributes to Apply: Select the key (data) you'd like to update, and then add the value you want the key to have.  For multiple changes, click the plus sign.
      For example, a group of events have a category of ‘None’ and the organization wants to categorize these events based on information contained within the event. Key = Category and the Value = Research
  4. Select Save to complete and enable your classifier.
  5. After setting up the classifier, you can search for _exists_:tag_queries to display events that have matched one or more classifiers.

Specifications for Classifiers

  • You must select to either drop, exclude, or apply an attribute to create a classifier.
  • If you create a classifier for ‘WDAP’, it matches all events that contain ‘WDAP’. If you create a classifier NOT ‘WDAP’, it matches events that do not contain ‘WDAP’. This is the opposite of writing NOT or - within command line text.
     

Edit/Pause/Delete

Pausing or deleting a classifier

Once the classifier is created, you have the option to pause, edit, or delete it. 

To edit a classifier

  1. Go to Events > Classifiers
  2. Select the classifier you want to edit
  3. Make desired changes
  4.  Click Save.

To pause a classifier

  1.  Click the power icon and it will toggle from blue to gray. 
    1. Blue - active
    2. Grey - paused
  2. Note: Pausing classifiers may take a short time to take effect.

To delete a classifier

  1. Go to Events > Classifiers
  2. Select the classifier you want to delete
  3. Click Delete. Note: Deleting classifiers may take a short time to take effect.