Automating AI Enrichment
Last updated
Was this helpful?
Last updated
Was this helpful?
Question Wizard is designed for users frequently asking questions about portal management. Users can manage sysmon data, process traffic status, threat analysis results, and AI enrichments. To use the Question Wizard, please click on the robot button on the upper right of the page.
After clicking the robot button, the Question Wizard modal will appear on the screen. Users can select predefined questions.
After the selection, users can add AI recommendations the artifacts or artifact collection rules. As an example, logs creating too much traffic ca be excluded in three steps:
1 - Click on the "Check All Recommended",
2 - Click on the "Add All Checked to Image & Network Access Exclusions",
3 - Click on the "Add All Checked to Exclusions (per Relevant Event ID)".
These actions will check all the recommended artifacts and add them to the specific exclusion fields for sysmon. With those actions, the unnecessary sysmon artifacts are excluded from the collection and analysis.
The sysmon exclusion lists can be observed from "Rules & Policies" -> "Artifact Collection Parameters" -> "Windows Sysmon Rules".