Log Data Enriched with User Context

Once you've chosen the log set to search against, you can enter your search query and start finding answers. Next, we'll enter our query to see firewall alerts by user.

2 of 5

Raw Logs, Enriched with User Context

Here is the raw log structured in a clear, JSON format. InsightIDR has further enriched the data by adding the "asset", "user", and "geoip" fields.

This automatic attribution serves as the foundation of the user behavior analytics used for incident detection and investigation.

View as Logs or Table

You can also view the data in a table format, and customize the displayed columns.

View Screenshot

Simple and Advanced Query Modes

With simple mode, you can easily build common use cases via point-and-click. The search will populate with the Log Entries Query Language (LEQL). You don't need to be a data wizard to get results.


Contact Us

We're happy to answer any questions you may have about Rapid7