Index Definitions & Details
Stellar Cyber organizes data into indices, which helps to speed up your searches.
The following table lists the name of each index in Stellar Cyber, the name of the index in the Interflow data, the type of data collected in that index, and the source of the data.
Stellar Cyber provides Coverage Analyzer and Detections & Response tools that let you look up alert types by sensor, data source, application, alert name, alert type, or by XDR attributes such as kill chain stage, tactic, or technique. You can also view alert types by index in Machine Learning Alert Types by Index, which provides links to descriptions of the alert types that can appear in each available index.
| Index | Interflow Name | Data Source |
|---|---|---|
| Alerts | aella-ser-* |
Security events from Machine Learning, security analytics, and ATH playbooks |
| Assets | aella-assets-* | Asset data based on Stellar Cyber analytics Connectors:
|
| AWS Events | aella-cloudtrail-* |
CloudTrail non-traffic logs Machine Learning alerts types for this Index Connectors:
|
| IDPS/Malware Sandbox Events | aella-maltrace-* |
Firewall threats from sensors/log forwarders Maltrace SDS/Sandbox |
|
Linux Events |
aella-audit-* |
Audit data from Linux agents Machine Learning alert types for this index Connectors:
|
| Scans | aella-scan-* |
Machine Learning alert types for this index Connectors:
|
| Sensor Monitoring | aella-ade-* |
Sensor statistics from DP Configuration Manager |
| Signals | aella-signals-* |
Sensitive events that are not alerts but may provide useful context in threat hunting. The following Windows events are stored in the Signals index: 104, 643, 1102, 4698, 4727, 4728, 4729, 4731, 4732, 4733, 4739, 4740, 4741, 4743, 4754, 4756, and 4757 |
| Syslog | aella-syslog-* |
Application logs from sensor log forwarder parsers Machine Learning alert types for this index Connectors:
|
| Traffic | aella-adr-* |
Flow traffic from sensors Machine Learning alert types for this index CloudTrail traffic Firewall traffic logs from sensor log forwarders DHCP server logs from sensors VPC Flow logs ICMP/IGMP logs Connectors:
|
| Users | aella-users-* |
User data from analytics Connectors:
|
| Windows Events | aella-wineventlog-* |
Machine Learning alert types for this index Active Directory connector user data
Windows logs from Windows agents Windows System Security logs Connectors:
|
