Score an event based on the past behavior of similar events. If an event is anomalous, a higher score is assigned.
- Click + on the parent node.
- Enter the Baseline Scorer operator in the search field and select the operator from the Results to open the operator form.
- In the Input Table drop-down, enter or select the table containing the data to run this operator on.
- In the Group By Field, enter the column name by which to group the rows by.
- In the Metric Field, enter the column name that contains the metric to be used for scoring.
- In the Baseline Table drop-down, enter or select the name of the baseline table.
- Click Run to view the result.
- Click Save to add the operator to the playbook.
- Click Cancel to discard the operator form.
baselineScorer(eventTable, groupByField, metricField, baselineTable)
eventTable: name of a step that contains the events to be scored
groupByField: name of a grouping field (or lookup field) in a table
metricField: name of a metric field in a table
baselineTable: name of a step that contains historical events
For example: let
XYZ table contain
bytes_downloaded fields. The baseline scorer operator identifies which IP addresses downloaded more or fewer bytes relative to the past.
The operator compares
XYZ table with historicalTable (which contains the historical events). Based on a statistical analysis it calculates whether the downloaded bytes for the particular IP address are out of range. If within range, the score is zero. If out of range, the score is based on how far from the range seen in the past (maximum score is 10).
In the example:
XYZ is an argument for
baselineScorer(XYZ, "ip", "bytes_downloaded", historicalTable)
Baseline scorer operator returns
eventTable with the original columns and two extra columns:
lhub_score: computed score
lhub_confidence_score: Confidence in the score based on the number of samples. 100 means there are enough samples to calculate the score; less than 100 means that there are fewer samples to calculate the score. The operator scores the events regardless of the number of samples, so
lhub_confidence_score is a measure of the confidence level for the score.
tableA contains a baseline (history) of files downloaded for each user.
tableB is today's data. baselineScorer compares today's data relative to the history to determine if the user downloaded more or fewer files (an anomaly).
baselineScorer(tableB, "user", "downloaded", tableA)
User "emil" downloaded many more files than usual. "monica" downloaded fewer files than usual but her activity was less out of range thatn "emil" in x3.
lhub_confidence_score is 100% in each case, indicating that there are enough samples for high confidence.
Updated almost 2 years ago