Deployment
HYPERCLOUD documentation
Deploy and operate Bloo in your own environment.
Start with the quickstartQuickstart
- HYPERCLOUD quickstartProvision a HYPERCLOUD environment and sign in.
- Getting Started with Bloo AIThe Bloo AI features in Bloo v9.0 assist our customers and employees in providing an elevated user experience using the Bloo console.
- Before You BeginBefore you install Bloo, ensure that the following requirements are met
- Pre-Requisites AuditThis document includes a script to conduct an audit to assure that all the pre-requisites are met for the successful deployment of Bloo.
- Quick Start GuideWelcome to the quick start guide,
- Your first FIND with the HYPERCLOUDWelcome to Bloo HYPERCLOUD
- PICO InstallationThis article will help you for PICO Installation
- Create a Code BlockCode Block also known as a Python Block is used to manipulate the data and generate a new output using python.
How-to guides
- Manage tenants and accessHow to manage tenants, tenant administrators, tenant users, and role-based access in Bloo.
- Define Custom Enrichment BucketThis is a documentation on how to create a custom enrichment
- Search APISearch API
- Advanced Telemetry for WindowsAdvanced Telemetry for Windows
- Extractor Generator OverviewExtractor Generator Overview
- Query by source nameThe Bloo Query Language supports querying by source name.
- How to Add a Connector?Connector
- Query multiple streamsThe Bloo Query Language lets you query multiple streams separated by a comma.
- Schema on ReadAccess Structured Data in your logs without Extraction.
- Enrich DevSrcIP with Asset StoreEnrich DevSrcIP with Asset Store
- Flag matches with GreenSnow ThreatIntelGreenSnow is a third-party threat intel integration source available with Bloo in the form of an external dataset integration. It is possible to obtain a list of malicious IP addresses seen in many environments using GreenSnow.
- Flag Risky User ActivitiesVarious users can be identified in logs for different streams ingested by Bloo. Multiple signals can be raised for a Suspected User, this leads to Suspected User being a Risky User.
- UBA: Coalescing User IdentitiesIn an organization, multiple identities could be associated to a specific user.
- View EnrichmentThis page will help you understand the step by step procedure to view the details of an enrichment.
- Custom ExtractorsBloo provides users with the flexibility to create custom extractors.
- View an ExtractorBloo library has extractors ready to ingest data from all types of devices
- Add Parameters to WorkbookWorkbook parameters can be referred to as the input to conditions that are used to filter query results or to provide input queries.
- Create a Call BlockCall block works on the principle of Reusability (Create once and Use Anywhere).
- Create a DQL BlockBloo uses its own Query Language known as DQL, a primary form of interaction with the Datanode to analyse and interpret the data.
- Create a Notification BlockNotification blocks allow you to send notifications to users via email, incorporating data received from the previous block into the notification.
- Create an Outlier BlockOutlier accelerates and automates the process of identifying a potential threat.
- Create an SQL BlockBloo supports query processing and analysis with SQL.
- Create a Return BlockIn the Workbook section, the Return Block is essential for managing the flow of control and data between different workbooks.
- Create a Search BlockSearch block has been added to create queries by selecting the predefined directives, filters, functions etc.
- Create a Signal BlockSignals help us look up within multiple attack vectors, signals are triggered via Workbooks i.e. as per the logic set in its query.
- Create a Text BlockText Block explains the use, description of the particular workbook, you can include details such as what can be achieved from this workbook, why it should be used and also include the various dependencies, steps to achieve the target result.
- Create a Visualisation BlockVisualisation Block will help you to interact through a visual interface to give a clear and direct insight to the underlying data.
- How to create a Workbook?We will understand here how to create a new workbook
- Native WorkbookNative workbooks are workbooks authored by Community and Bloo
- Schedule a WorkbookA Workbook with a collection of queries can be saved and scheduled to run at set intervals.
- Working with Pass through ContentSignature based threat detection always works as a one hit wonder for the organizations due to its ease in determining the presence of malicious entities in our network or systems.
- Add comment to the signalIf you want to add a comment to the signal
- Add Multiple Signals to a CaseHere you will get the idea about how to add multiple signals to case
- False PositivesA false positive is a false alarm. This occurs when the system identifies an attack and triggers an alarm but it is acceptable behavior.
- Graph View for SignalsIn any environment, during the process of collecting, processing and analysing data, outliers can come from many sources and hide in many dimensions.
- How to add a signal to a case?Signal is an individual event that would be indicating any suspicious or malicious event, but by itself it is not an incident.
- Investigate AnywhereWith Investigate Anywhere you can dig deep into security event logs and investigate incidents faster.
- Raise and View SignalsYou can raise a signal from the workbook by adding a Signal Block.
- Signal Data exportUsers can now export Signal data from the Signal listing page to analyze it further.
- Signal FiltersThis feature allows you to customize the signals list view, by applying the specific filters you can view only what is required.
- View Signal Context DetailsThis allows you to fetch all the incidents in the raw log where the particular entity is repeated.
- Create a DashboardA Dashboard is an element of a graphical user interface (GUI) that displays information of different widgets to a single place or provides a specific way for a user to interact with Bloo.
- Notification for PICO and Data Source eventsTenant administrators can configure email addresses to receive notifications for key events on PICO.
- Working with ServicesThis section helps you to manage and monitor the services of PICO.
- Change Task TimeoutsTo change the default task timeout configuration for celery workers
- Collection StatusBloo library has extractors ready to ingest data from all types of devices.
- Event StoresAn event store is simply a data store for all the events where you can rapidly analyze the data.
- LDAP AuthenticationLDAP is a type of software protocol that allows individual users and applications to find and verify whatever information they need within their organization.
- Machine LearningMachine learning (ML) is used to analyze the incoming data that matches the set filters, it allows you to apply multiple ML models to a single stream of data.
- Manage TokenToken management is the process used to authenticate third party applications to access Bloo Integration Services.
- Managing StreamsStream Management is management of a specific collection of data that is used as a log.
- SAML Authentication SupportBloo provides SAML Authentication
- Slow QueriesThe Slow Queries page displays lists of all queries that have been running/processing for a long time but haven't completed yet.
- Two-Factor AuthenticationTwo-Factor Authentication, adds an extra layer of protection to your system and intranet/extranet login.
- Create a ReportHow to create a new report
- Invoke/Revoke a reportHow to revoke a report
- Schedule a reportHow to schedule a report
- View ReportsHow to view a report
- Export Case DataThe Export feature simplifies downloading case information, enabling users to access detailed case data and notes for selected cases.
- Manage CasesManaging Cases allows users to effectively handle and update existing Cases to ensure smooth workflows and accurate record-keeping.
- Search and Filter CasesSearching and filtering cases allow users to quickly locate and focus on specific cases by applying relevant filters
- Creating Signal Suppression RulesCreating Signal Suppression Rules from Signal Suppression Rules Listing page
- Streamline Alert Analysis with Signal TaggingStreamline Alert Analysis with Signal Tagging
- Workbook Versioning: Track, Collaborate, and Restore with EaseWorkbook Versioning: Track, Collaborate, and Restore with Ease
- Create & Edit UsersCreate & Edit Users
- Delete a UserDelete a User
- Edit OrganisationEdit Organisation
- Enable or Disable a UserEnable or Disable a User
- Reset a User's PasswordReset a User's Password
- Organization Audit TrailOrganization Audit Trail
- Reset MFAReset MFA
- FortiGateAutomation examples for taking action on FortiGate servers, including adding and removing hosts from address groups.
- View UsersView Users
- Manage Role-based AccessManage Role-based Access
- Palo Alto: Add to Group / Remove from GroupHow to automate firewall host group updates on Palo Alto devices using SSH-based actions.
- Manage Tenant AdministratorManage Tenant Administrator
- Secure Compromised User AccountAutomation examples for securing a compromised user account using Bloo SSH integration.
- How to Configure Connectors?How to configure a connector instance to directly ingest logs into Bloo from the Data Source screen.
- Manage Tenant UserManage Tenant User
- How to Configure Connectors? (Legacy console)How to configure a connector instance from the Manage Components screen in the legacy console.
- View Tenant & Edit TenantView Tenant & Edit Tenant
- Syslog (Data Ingestion)How to ingest syslog data into Bloo via UDP port 514 with no additional configuration.
- Syslog (Data Ingestion) (Legacy)Legacy steps for ingesting syslog data into Bloo via UDP port 514.
- Windows Event LogsHow to enable command line logging and forward Windows Event Logs to Bloo using NXLog.
- Windows Event Logs (Legacy)Legacy steps for forwarding Windows Event Logs to Bloo using NXLog.
- Sync Cases to ITSM ToolHow to configure the ITSM Webhook automation and sync case updates to any ITSM tool.
Connectors
- AlienVault OTXAlien vault OTX
- Asset StoreAsset store
- GreenSnowGreensnow
- Active DirectoryActive directory
- ClickSendclick send
- Domain Toolsdomain tools
- JiraServiceDeskJiraservicedesk
- Microsoft Teams ChannelMicrosoft Teams Channel
- New RelicNew Relic
- OpsgenieOpsgenie
- PagerDutyPagerDuty
- Palo Alto: Add to Group / Remove from GroupPalo Alto: Add to Group / Remove from Group
- Palo Alto Firewall Automation (Block / Unblock)Palo Alto Firewall Automation (Block / Unblock)
- ServiceNowServiceNow
- Slack ConfigurationSlack Configuration
- TAXIITaxii
- Trend MicroAutomation Guide for Bloo
- URLhausAutomation Guide for Bloo
- User StoreAutomation Guide for Bloo
- VirusTotalAutomation Guide for Bloo
- WebhookAutomation Guide for Bloo
- SSH ConfigurationAutomation Guide for Bloo
- 1Password ConnectorConnectors in Bloo
- Abnormal Security ConnectorConnectors in Bloo
- Akamai NetStorage ConnectorConnectors in Bloo
- Atlassian ConnectorConnectors in Bloo
- Auth0 ConnectorConnectors in Bloo
- AWS CloudTrail ConnectorConnectors in Bloo
- AWS GuardDuty ConnectorConnectors in Bloo
- AWS Kinesis ConnectorConnectors in Bloo
- AWS S3 Optimized Cross Account ConnectorConnectors in Bloo
- AWS S3 (Optimized) ConnectorConnectors in Bloo
- AWS S3 ConnectorConnectors in Bloo
- Azure Blob Storage ConnectorConnectors in Bloo
- Azure Event Hub ConnectorConnectors in Bloo
- Azure NSG ConnectorConnectors in Bloo
- Beats ConnectorConnectors in Bloo
- Box ConnectorConnectors in Bloo
- Cisco Duo ConnectorConnectors in Bloo
- CloudWatch ConnectorConnectors in Bloo
- Cortex XDR ConnectorConnectors in Bloo
- CrowdStrike ConnectorConnectors in Bloo
- Cyble Vision ConnectorConnectors in Bloo
- Device42 ConnectorConnectors in Bloo
- Dropbox ConnectorConnectors in Bloo
- GCP Pub/Sub ConnectorConnectors in Bloo
- GCP ConnectorConnectors in Bloo
- GitHub ConnectorConnectors in Bloo
- Google Workspace ConnectorConnectors in Bloo
- Haltdos ConnectorConnectors in Bloo
- HTTP ConnectorConnectors in Bloo
- HubSpot ConnectorConnectors in Bloo
- Indusface ConnectorConnectors in Bloo
- Jira ConnectorConnectors in Bloo
- JumpCloud ConnectorConnectors in Bloo
- Microsoft Exchange Online ConnectorConnectors in Bloo
- Microsoft Graph Security API ConnectorConnectors in Bloo
- Microsoft Intune ConnectorConnectors in Bloo
- Microsoft Sentinel ConnectorConnectors in Bloo
- Mimecast ConnectorConnectors in Bloo
- Netflow ConnectorConnectors in Bloo
- Netskope ConnectorConnectors in Bloo
- Network Traffic Analysis ConnectorConnectors in Bloo
- Office 365 ConnectorConnectors in Bloo
- Okta ConnectorConnectors in Bloo
- OneLogin ConnectorConnectors in Bloo
- Orca ConnectorConnectors in Bloo
- PICO Legacy ConnectorConnectors in Bloo
- Prisma Alerts ConnectorConnectors in Bloo
- Prisma Incidents ConnectorConnectors in Bloo
- RediffMail Pro ConnectorConnectors in Bloo
- Salesforce Pub/Sub ConnectorConnectors in Bloo
- Salesforce ConnectorConnectors in Bloo
- Shopify ConnectorConnectors in Bloo
- Slack ConnectorConnectors in Bloo
- Snowflake ConnectorConnectors in Bloo
- Snyk ConnectorConnectors in Bloo
- Sophos ConnectorConnectors in Bloo
- Syslog ConnectorConnectors in Bloo
- TCP ConnectorConnectors in Bloo
- TLS ConnectorConnectors in Bloo
- Tenable Security Center ConnectorConnectors in Bloo
- Tenable Vulnerability Management ConnectorConnectors in Bloo
- Trend Micro Audit Logs ConnectorConnectors in Bloo
- Trend Micro Vision One ConnectorConnectors in Bloo
- Workday HCM ConnectorConnectors in Bloo
- Zendesk ConnectorConnectors in Bloo
- Zoom ConnectorConnectors in Bloo
Troubleshooting
- Extractor ValidatorThe extractor validator is a valuable feature that assists users in validating the extractors developed
- Apache Log4j CVE-2021-44228Apache Log4j CVE-2021-44228
- Support HandbookHandbook
- Active Threat Content SynchronizationActive threat
- Service Limits for Bloo Cloudservice limits
- Scaling DatanodesSolution design for scaling datanodes
- Scaling AdaptersSolution design for scaling adapters
- Minimum RequirementsSolution design for minimum requirements
- Hardware benchmarkSolution design for hardware benchmark
- Connector ValidationHow Bloo validates connector configuration and where to see the validation status.
- Troubleshooting AutomationsThe list of automation validation statuses and how to troubleshoot each one.
- Troubleshooting Connector ValidationsCommon connector validation error messages and their troubleshooting instructions.
Reference
- Bloo End-user License AgreementEnd user License
- Data Query Language Basic SyntaxData Query Language Basic Syntax
- Data Privacy PolicyThis Privacy Policy
- EnrichmentBloo provides real-time and customizable event data enrichment which reduces overall investigation times.
- DQL CHEATSHEETEasy to work with query samples for DQL. Use them as a starting point in building your queries.
- Term Based Software SubscriptionBloo Subscriptiom
- _aggThe _agg query directive is used to perform aggregations on the result set.
- _checkif**_checkif** is a query directive used to apply conditional logic on a result set.
- _export_export is a query directive used to extract a result set from the pipeline and send it to your email inbox.
- _limit_limit is a query directive used to limit the number of rows in a result set to the integer value specified in the query function.
- _fetch_fetch is extremely versatile and in most cases the first query function in your analytic. It is used to retrieve data from your datanode.
- _lookup_lookup is a query directive used to make API calls to third party databases.
- _retrieveReads data from an event store created using the _store directive.
- Schema on Read (Legacy)Access structured data in your logs without extraction using the @ field prefix.
- _sort_sort is a query directive used to sort the result set.
- _storeThe _store directive is used to write and store the result set, permanently on the hard disk, for later use.
- _trigger_trigger is a query directive used to perform an action in response to an event or investigation, typically via an API call.
- DQL - Right from the startAn introduction to the Data Query Language pipeline model and what it is used for across Bloo.
- AvgThe AVG function is an aggregate function that calculates the average value of a set.
- Count_ifThe count_if function returns the number of records that satisfy the condition.
- Distinct_countThe distinct_count function lets you count unique occurrences of values of a specified field in the result set.
- DistinctThe distinct function is used to avoid duplicate values present in any specific columns/table.
- LengthThe length function returns the length of a string.
- MaxThe MAX function allows you to find the maximum value in a set of values.
- MinThe MIN function returns the minimum value in a set of values.
- Not ClauseNOT is a logical operator in DQL used to select rows for which a conditional statement is false.
- Percentage_ofThe Percentage_of function calculates the percentage value where the condition is met.
- Ratio_ofThe ratio_of function computes the ratio value where the condition is met.
- Regex MatchA Regular Expression (RegEx) is used to match patterns with various sequences of characters in DQL.
- SumThe SUM function is an aggregate function that returns the sum of all or distinct values.
- WildcardBloo DQL supports wildcard operators in conjunction with the LIKE operator.
- OverviewDQL (Bloo Query Language) is a powerful, yet simple, query language that helps to analyze data with ease.
- DurationThe duration pipe lets you specify the start and end timestamp for retrieving events.
- FirstThe first keyword picks the oldest or earliest events to be a part of the result set.
- GroupbyThe groupby pipe helps organize data in groups and calculate aggregate statistics for those groups.
- Having ClauseA HAVING clause in DQL specifies that a SELECT statement must only return rows where aggregate values meet specified conditions.
- LastThe last keyword picks the newest/latest events first and limits the number of events in the final result set.
- LimitLimit indicates the maximum number of results that should be returned by the query.
- SelectThe Select pipe helps you retrieve only the data that you want and combine data from different sources.
- TimesliceGives a count of events in each bucket (time interval) using the timeslice pipe.
- Guidelines for Sanitizing Log SamplesGuidelines for sanitizing log samples to protect PII and sensitive data before sharing.
- How Extractors work?How Bloo extracts relevant data from incoming events using extractors.
- Understanding ExtractorsHow extractors translate and transform events from multiple devices into a common context.
- How to view Workbooks?How to view the folder-wise list of existing workbooks in a tenant.
- Workbook FunctionsThe various icons and functions available on the Workbook page.
- WorkbooksAn overview of Workbooks and the blocks used to build them.
- Global SignalsThe global signals feature helps you view and respond to attacks across multiple clusters.
- Signal Confidence LevelsThe Confidence Score is a dynamic metric assigned to each signal generated by detection workbooks.
- Source StreamSource streams are the log sources on your network, categorized by infrastructure, security, applications, and servers.
- Suspect & TargetEvery signal has a suspect responsible for it and a target affected by it.
- What are signals?A signal is a possibility of a potential threat raised from a workbook.
- Signal Context DetailsSignal Context details help you understand entities related to the suspect or target entity.
- Signal Suppression RuleSuppression rules let you suppress signals triggered by known sources and activities.
- What is Security Monitoring?Security monitoring continuously monitors and flags vulnerabilities and security problems.
- Why EBAEntity Behavior Analytics identifies risky users and anomalous behavior within the network.
- Adapter SafeguardsAdapter Safeguards protect the Adapter from possible failures such as EPS overload or cache pileup.
- Bloo EntitiesDefinitions and meanings of Bloo entities such as Organization, User, Tenant, and Scope.
- Manage UsersHow user management and the Cluster Administrator role work in Bloo.
- Password PolicyThe password complexity, reset, and session timeout policies applied to Bloo console users.
- Geo EnrichmentGeo enrichment contextually enriches IP addresses in log data with geographic location intelligence.
- View CasesHow to view the case listing page, case statistics, and case details in Bloo.
- Calculating OverageHow overage is calculated on Bloo HYPERCLOUD, including buffer zones and billing cycles.
- Pricing to Billing: How it WorksHow Bloo HYPERCLOUD pricing translates to your bill and why it is configured the way it is.
- Detection Coverage on MITRE ATT&CK frameworkHow detection coverage across the MITRE ATT&CK framework is visualized through heatmaps in Bloo.
- MITRE ATT&CK® and BlooHow the MITRE ATT&CK framework helps Bloo understand attacker behavior and automate threat detection.
- MITRE ATT&CK OverviewAn overview of the MITRE ATT&CK page and how detection workbook coverage maps to the framework.
- Signal Activity mapped to MITRE ATT&CK frameworkHow the Signals tab displays techniques associated with workbooks that have triggered signals.
- Case LifecycleThe stages a case in Bloo undergoes from creation to closure.
- Case Management OverviewAn overview of case management in Bloo and how it streamlines incident response.
- Create a CaseHow to create a new case from one or more signals in Bloo.
- Key Metrics - MTTD, MTTA & MTTRHow Bloo calculates Mean Time to Detect, Acknowledge, and Resolve for cases and signals.
- Kill Chain ModelHow the kill chain model maps to MITRE ATT&CK techniques and tactics in Bloo.
- Availability TimelineHow to create an availability timeline chart in a Bloo workbook.
- Bipartite ChordHow to create a bipartite chord diagram in a Bloo workbook.
- Bubble ChartHow to create a default or stacked bubble chart in a Bloo workbook.