From the Cortex XSIAM tenant you can view the sequence (or timeline) of events and alerts that are involved in any particular threat.
The Timeline provides a forensic timeline of the sequence of events, alerts, and informational BIOCs and Correlation Rules involved in an attack. While the Causality View of an alert surfaces related events and processes that Cortex XSIAM identifies as important or interesting, the Timeline displays all related events, alerts, and informational BIOCs and Correlation Rules over time.
Note
The Timeline View is not available when investigating cloud Cortex XSIAM alerts and Cloud Audit Logs or SaaS-related alerts for 501 audit events, such as Office 365 audit logs and normalized logs. Only the applicable Cloud Causality View and SaaS Causality View is available for this data.
Cortex XSIAM presents the Timeline in four parts:
Section | Description |
---|---|
CGO (and process instances that are part of the CGO) | Cortex XSIAM displays the Causality Group Owner (CGO) and the host on which the CGO ran in the top left of the timeline. The CGO is the parent process in the execution chain that Cortex XSIAM identified as being responsible for initiating the process tree. In the example above, |
Timespan | By default, Cortex XSIAM displays a 24-hour period from the start of the investigation and displays the start and end time of the CGO at either end of the timescale. You can move the slide bar to the left or right to focus on any time-gap within the timescale. You can also use the time filters above the table to focus on set time periods. |
Activity | Depending on the type of activities involved in the CI chain of events, the activity section can present any of the following three lanes across the page:
The lanes depict when the activity occurred and provide additional statistics that can help you investigate. For BIOC, Correlation Rules, and Alerts, the lanes also depict activity nodes, highlighted with their severity color: high (red), medium (yellow), low (blue), or informational (gray), and provide additional information about the activity when you hover over the node. |
Related events, alerts, and informational BIOCs | Cortex XSIAM displays up to 100,000 alerts, BIOCs and Correlation Rules (triggered and informational), and events. Click on a node in the activity area of the Timeline to filter the results you see here. Similar to other pages in Cortex XSIAM , you can create filters to search for specific events. |