Job Tracking
The turbosearch operator enables you to search for a list of indicators in your data, including historic as well as incoming data.
Specifically, you can check whether or not any parsed fields or the raw message contain any indicators of compromise, up to 20 indicators, for the following indicator types:
-
IP address
-
Filepath
-
File names
-
File hashes
-
Registry keys
If the list of IOCs exceeds 20 indicators, turbosearch will automatically turn this search into a background job.
Monitor background jobs
To monitor a background job, navigate to Search > Manage > Job Tracking.
|
|
Captures the AQL search expression using turbosearch. See the turbosearch operator page to learn more about creating turbosearch search queries. |
|
|
Output lookup table that is automatically generated by the background job when there are > 20 IOCs. You can click on the generated lookup table to view the results on the Search page for further analysis. If your query uses the For example, in the query below, the yieldtable operator appends the results into the
|
|
|
Indicates the status of the background job. Possible values are:
|
|
|
Total number of records in the output lookup table the background job automatically generates. |
|
|
Total number of Anomali Virtual Compute (AVC) units the job has consumed. See AVC for more information. |
|
|
Expiry date of the lookup table the background job automatically generates. Default expiry duration is 30 days from the time the job is completed. |
|
|
Job ID of the background job that is automatically triggered by turbosearch, letting you can access the output lookup tables once the job is complete. |
|
|
Type of the job. |
|
|
Date the background job was created. |
|
|
Email credentials of the user that triggered the background job. |
|
|
Search for an output lookup table by its Job ID, once the job is complete. |