Skip to content

Commit 801b245

Browse files
author
Karima Rafes
committed
Correction of indentations
1 parent d4ec8f3 commit 801b245

File tree

1 file changed

+12
-12
lines changed

1 file changed

+12
-12
lines changed

docs/build/tutorial-how-to-link-ids-to-osint/define-the-need/index.md

Lines changed: 12 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -71,13 +71,13 @@ After several propositions, analysts oriented the implementation of our first da
7171
In this tutorial, we study only this first result:
7272

7373
!!! example "Expected result"
74-
A knowledge graph will reduce the time required to research details on the Web of each new alerts in the IDS of IN Analysts.
75-
To achieve such savings we aggregate all links of sources and references about alerts in the Security information and event management (SIEM) in a knowledge graph.
76-
Analyst are able to read the Mitre information directly in his timeline (e.g. in SPLUNK) and to access all references about an alert from this central place.
74+
A knowledge graph will reduce the time required to research details on the Web of each new alerts in the IDS of IN Analysts.
75+
To achieve such savings we aggregate all links of sources and references about alerts in the Security information and event management (SIEM) in a knowledge graph.
76+
Analyst are able to read the Mitre information directly in his timeline (e.g. in SPLUNK) and to access all references about an alert from this central place.
7777

78-
![](slide_result_expected.png)
78+
![](slide_result_expected.png)
7979

80-
*Figure 1. Example of expected results for analysts during the task to understand the meaning and relevance of new alerts in their IDS.*
80+
*Figure 1. Example of expected results for analysts during the task to understand the meaning and relevance of new alerts in their IDS.*
8181

8282
When we know the waited results, we can imagine the necessary use cases.
8383

@@ -98,15 +98,15 @@ In this tutorial, after to test this first result, we claim a knowledge graph ca
9898
Another result of this project was to resolve this other need:
9999

100100
!!! example "For who"
101-
IN analysts
101+
IN analysts
102102
!!! example "What"
103-
Calculate and manage their investigations' knowledge graphs of high-level and low-level directly in Splunk
103+
Calculate and manage their investigations' knowledge graphs of high-level and low-level directly in Splunk
104104
!!! example "Context"
105-
Linking IDS events to a knowledge graph can be complex.
106-
This is for several reasons like labels/IDs/structures of the same resources can be different.
107-
Corporate Memory provides advanced capabilities to perform this in an automatic way.
108-
To use these tools, we need to export the data of SPLUNK to Corporate Memory.
109-
Analysts need to export data from SPLUNK to Corporate Memory on the fly and execute Corporate Memory workflows with reconciling complex data automatically and SPARQL update queries directly triggered via their SPLUNK dashboards.
105+
Linking IDS events to a knowledge graph can be complex.
106+
This is for several reasons like labels/IDs/structures of the same resources can be different.
107+
Corporate Memory provides advanced capabilities to perform this in an automatic way.
108+
To use these tools, we need to export the data of SPLUNK to Corporate Memory.
109+
Analysts need to export data from SPLUNK to Corporate Memory on the fly and execute Corporate Memory workflows with reconciling complex data automatically and SPARQL update queries directly triggered via their SPLUNK dashboards.
110110

111111
For the moment, we are searching the best way to resolve this need but a demonstrator to manage several investigations in the same knowledge graphs is available with several examples of dasboards in the Splunk app "[Investigate lateral movements with a knowledge graph](../link-IDS-event-to-KG-via-cmem/eccenca_poc_investigate.tar.gz)" ([tutorial page](../link-IDS-event-to-KG/index.md)). This need is for advanced users of Corporate Memory and it may be proposed in a future tutorial.
112112

0 commit comments

Comments
 (0)