Glossary
Analyst | Administrator5 min
What it's for
Quick reference for terms used in documentation and the Affinity interface.
Terms
- Alert — Security event generated by a rule.
- Detection Rule — Scheduled query that generates alerts.
- Integration — Connection to a log source.
- Secret — Securely stored credential.
- Notification Channel — Destination (Slack, Discord, etc.) for alerts.
- IOC — Indicator of compromise (IP, domain, hash…).
- Query — SQL search over your logs in Affinity.
- Ingestion / Enqueue — Process of bringing logs into the platform.
- Analyst — User who investigates alerts and logs.
- Administrator — User with Management access.