Documentation forSecurity Event Manager

Search query tags and thresholds

You can apply tags to queries so they can be grouped for use with the Scheduled Query Severity and Scheduled Query Table Severity widgets on the SEM dashboard. For example, you could apply the End User Monitoring tag to all queries relating to End User Monitoring.

Additionally, you can apply threshold values to search queries. This process allows you to set the number of occurrences for each evaluation that results in an event query result being deemed critical, warning or OK severity.

Apply tags to a query

  1. In the toolbar, click Historical Events.
  2. In the left column, click the Queries tab.

  3. Maximize the targeted query category and select the query you want to edit.

    For example:

    A query tagged with the Editable icon can be edited, renamed and saved. A query tagged with the Use Only icon can be used but not edited. You can copy and rename the query, which can be edited.
  4. Click the vertical ellipsis and select Edit in the drop-down menu.

  5. In the Edit screen, ensure that the Details tab is selected.

  6. Click Add tag and select the required tag or tags to apply to this query. Tags applied to the query are displayed above the Add tags link.

  7. Click Add.

After you select one or more tags, specify the thresholds that determine whether event search results display as Critical, Warning or OK on the dashboard widgets.

Thresholds

You can apply threshold values to search queries to set the number of occurrences per evaluation (that is, when the query was last run) that result in an event query result being deemed critical, warning or OK severity.

Once you have set up tags and thresholds for a query, you can use this data to set up widgets on the SEM dashboard.

Widgets

The scheduled query widgets are created and customized in the same way as other SEM Dashboard widgets.

Scheduled Query Table Severity widget

The following widget has been customized to list all search queries that have returned one or more event within the most recent evaluation. It shows the number of occurrences and the time the query was last run.

Scheduled Query Severity widget

Click the red, yellow or green area of the query severity widget to display the corresponding query on the Historical Events page.

If more than one query is tagged, the Manage Saved queries window will display, listing all queries that apply to this severity level