Orientation: Your First 15 Minutes
Analyst15 min
What it's for
In fifteen minutes you can walk through the full platform cycle and feel in control.
Steps
- Review alerts: Sidebar → ALERTS. Explore the `Critical`, `High`, `Medium`, `Low` cards.
- Explore logs: Sidebar → LOGS. Switch to Query Editor and run a query with Run Query.
- Try an investigation: Sidebar → INCIDENT RESPONSE. On the Text Input tab, paste sample text with Load Example and click Extract IOCs.
Expected result
- You know the three main areas: alerts, logs, and incident response.
- You understand the basic detection and investigation flow.
Tips
- You don't need real data to try Incident Response — Load Example includes sample IOCs.
- If you don't see logs, ask your administrator to verify integrations.