Skip to main content

Using Tags with Insights, Signals, Entities, and Rules

What are tags?

Tags are metadata you can attach to Insights, Signals, Entities, and Rules. Tags are useful for adding context to these Cloud SIEM items. You can also search for and filter items by tag.

There are two types of tags: 

  • Schema keys. These are predefined key-value pairs, which are useful for ensuring that users use  consistent values when assigning tags to items. There are two built-in schema tags: Tactic and Technique, which relate to the Mitre ATT&CK framework.

    You can create your own schema tags as well, as described in Create a Custom Tag Schema. You can optionally configure a URL for each value in a custom tag schema. If you do, a user will be able to open that URL from the tag’s Action menu when it’s presented in the Cloud SIEM UI. See Tag Actions below for an example.

    You can assign schema key tags to custom Rules you’ve developed.  For  built-in rules, you can assign or delete new  schema tags, but you can’t change or remove the tags that come with the rule. You can also assign schema key tags to Insights, both Cloud SIEM-generated and custom.  

  • Keyword tags. These are arbitrary labels that you define yourself. You can assign keyword tags to custom Rules, Entities, and Insights, both Cloud SIEM-generated and custom. You can’t remove or change the tags that come with built-in rules. 

A tag attached to a Rule is applied to Signals that the Rule generates. Similarly, tags applied to a Signal are applied to the Insights the Signal contributes to. All of the tags applied to an Insight's contributing Signals are aggregated, de-duplicated, and applied to the Insight. Note that an item is tagged when it is created. So, if you add a tag to a rule, Signals and Insights created before you updated the rule will not have that tag applied.

Tags and types

Some items that support tags in Cloud SIEM can be tagged explicitly from the Cloud SIEM UI. Some can inherit tags from another item. The table below summarizes this behavior.

TypeSupports explicit tag assignment?Items inherit tags from...
Built-in ruleyes-
Custom ruleyes    -
Custom Insightyes    -
System-generated Insightyes    Rule(s), Entity, Custom Insight
Entityyes    -
SignalnoRule(s), Entity

View tags

You can view tags on the pages that provide summary views of Insights, Signals, Entities, and Rules. You can also view the tags assigned to an item on the detailed page you see when you navigate to a particular Insight, Signal, Entity, or Rule. 

This is an overview of an Insight from the Insights page. Multiple schema key tags are attached to the Insight.

Insight list tags

The screenshot below shows an Entity to which a schema tag is attached.

Entity list tags

Tag actions

The actions menu for a tag allows you to:

  • Open an URL, if the tag is a schema tag, and an URL is configured for the selected tag value.
  • Copy the raw tag to your clipboard.
    Tag actions

Find the tagging UI

The procedure for tagging Rules, Entities, and Insights is similar. The difference is where you do the tagging. 

UI for tagging a Rule

  1. Select Rules from the Content menu.
  2. Navigate to a custom rule.
  3. The UI for tagging is at the bottom of the Then Create a Signal area of the Rule Editor.
  4. To add a tag, follow the instructions in Add a schema key tag or Add a keyword tag.
    Tag a rule

UI for tagging an Entity

  1. Click the Entities tab at the top of the Cloud SIEM UI.
  2. Navigate to the Entity to which you want to attach a tag.
  3. The UI for tagging is at the bottom of the Details pane.
  4. To add a tag, follow the instructions in Add a keyword tag.
    Tag an Entity

UI for tagging an Cloud SIEM-generated Insight

Note that in addition to tags that you manually assign to an Insight, an Insight will inherit any tags that were applied to the content that went into the Insight—the entity and the rule(s) or custom insight definitions that created the included signals—will automatically be inherited (and aggregated) by the Insight. 

  1. Click the Insight tab at the top of the Cloud SIEM UI.
  2. Navigate to the Insight to which you want to attach a tag.
  3. The UI for tagging is at the bottom of the Details pane.
  4. To add a tag, follow the instructions in Add a schema key tag or Add a keyword tag.
    Tag an Insight

UI for tagging a custom Insight

  1. Select Custom Insights from the Content menu.
  2. Navigate to a custom Insight.
  3. The UI for tagging is at the bottom of the Then Create a Signal area of the Insight Editor.
  4. To add a tag, follow the instructions in Add a schema key tag or Add a keyword tag.
    Tag a Custom Insight

Apply a schema key tag

  1. Navigate to the item to which you want to add a tag, as described in the previous section. 
  2. In the tagging section, click the chevron icon.
    Chevron icon
  3. Click a tag under Schema Keys.
    Tag list
  4. A list of values appears. 
    Tag list
  5. Select a tag value, and press Return to add it to the item. 

Apply a keyword tag

  1. Navigate to the Rule, Entity, or Insight to which you want to add a tag, as described in Find the tagging UI.
  2. In the tagging section, click the chevron icon.
    Chevron icon
  3. A list of keyword tags that have already been assigned to items of the current type (Rule, Entity, or Insight) appears. You can select an existing tag, or add a new one. Enter text in the field to see a list of matching values.
    Freeform tag list
  4. To add a new tag, enter it and press Return.
    Add freeform tag 
  5. The tag is added to the item.
    Freeform tag added 

Search by tag

Search Insights, Signals, or Entities by tag

  1. In the top menu, click in the Cloud SIEM search area and then click the funnel icon.
    Funnel icon
  2. Select Insights, Signals, or Entities from the Sources list.
    Sources
  3. Select Tags from the Fields list.
    Tags field
  4. Choose contain or do not contain from the Operators list.
    Operators
  5. Select a tag from either the Schema Keys or Keyword Tags list. If you select a tag from the Schema Keys list, you are prompted to select a value, and items that match are listed. If you select a tag from the Keywords list, items that match are listed.

Search Rules by tag

  1. In the top menu, click Content and select select Rules.
  2. Click in the Filters area and select Tags from the Fields list.
    Search rules by tag
  3. Choose contain or do not contain from the Operators list.
    Operators
  4. Select a tag from either the Schema Keys or Keyword Tags list. If you select a tag from the Schema Keys list, you are prompted to select a value, and items that match are listed. If you select a tag from the Keywords Tags list, items that match are listed. Note that if an item has a Mitre-related tag, an icon appears next to it. Click the icon to view a Mitre page on the Tactic or Technique.
Search results

Filter a list view by clicking a tag

On the Insights, Signals, Rules, or Entities page, you can click a tag to filter the list. For example, if you click the Tactic:TA0005 - Defense Evasion tag on an Insight, like this:

Filter list by tag

the page will be filtered to show only Insights that have that tag:

Filtered list

 

Status
Legal
Privacy Statement
Terms of Use

Copyright © 2024 by Sumo Logic, Inc.