Skip to content

Latest commit

 

History

History

SIEM-Dashboards

Phishing Intelligence Engine
LogRhythm Security Operations
v1.0  --  November, 2017

Copyright 2017 LogRhythm Inc.
This content is licensed pursuant to the LogRhythm End User License Agreement

[About]

These dashboards integrate with the LogRhythm SIEM and allow for easy searching, correlation, and automation.

[Install and Usage]

1) Office365-Analytics_Dashboard.wdlt

This dashboard is the main analytics dashboard, which highlights external to internal mail traffic, reported phishing attacks, and case metrics.

PIE Dashboard

2) Office365-Threat-Map_Dashboard.wdlt

Similar to the Analytics dashboard, however this is centered around the threat map, highlighting the origin location of email traffic.

PIE Threat Map

3) Email_Investigation.wdlt

The Investigative dashboard - implement this as a drilldown dashboard, allowing for easy analysis, searching, and correlation in the SIEM.

PIE Analyst Dashboard

You may need to update the Common Event field in each dashboard, to ensure this matches with what you defined for log parsing

[License]

Copyright 2017 LogRhythm Inc.

This content is licensed pursuant to the LogRhythm End User License Agreement located at https://logrhythm.com/about/logrhythm-terms-and-conditions/ (“License Agreement”) and by downloading and using this content you agree to the terms and conditions of the License Agreement unless you have a separate signed end user license agreement with LogRhythm in which case that signed agreement shall govern your licensed use of this content. For purposes of the applicable end user license agreement, this content constitutes LogRhythm Software