Query IOCs in Logs
RoleAnalystRead10 min
What it's for
Expand the investigation by searching extracted IOCs across your entire log infrastructure.
Steps
- 1
After extracting IOCs, select relevant indicators in the results list.
- 2
Click Query Selected in Logs.
- 3
Review results in the Security Logs drawer.
- 4
From there you can go deeper with filters, export, or send more context to investigation.
Expected result
- Log events containing or relating to the selected IOCs.
Tips
- Combine multiple IOCs to understand the full scope of the incident.
- The generated query uses Presto SQL: IPs with
IN (...), domains/URLs withLIKE '%...%'andLIMIT 100.