Updated on 2023-10-31 GMT+08:00

Security Analysis Overview

The security analysis function works as a cloud native security information and event management (SIEM) solution in SecMaster. It can collect, aggregate, and analyze security logs and alarms from multiple products and sources based on predefined and user-defined threat detection rules. It helps quickly detect and respond to security incidents and protect cloud workloads, applications, and data.

Limitations and Constraints

  • A maximum of 500 results can be returned for a single analysis query.
  • A maximum of 50 shortcut queries can be created in a pipeline. That is, a maximum of 50 query analysis criteria can be saved as shortcut queries.
  • A maximum of 5 data spaces can be created in a workspace, and a maximum of 20 pipelines can be created in a data space.
  • A maximum of 64 shards can be allocated to a pipeline.
  • The maximum data retention period in a pipeline is 180 days.