🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Data Sources

integrations data sources


The Data Sources table provides an overview of the data sources sending telemetry to Secureworks® Taegis™ XDR with an indicator of their logging health. To access the Data Sources page:

  1. Select Integrations from the XDR left-hand side navigation.

  2. Choose Data Sources.

The table lists each data source XDR is aware of, including the sensor type and health status.

Manage Data Sources

Manage Data Sources

To make visualization clearer, data sources with multiple sensor types are grouped together in a single line by Source ID in the Data Sources table. If there are multiple sensor types rolled up to the source ID, you’ll see them listed in the table under the Sensor Type column.

Sensor Type Column

Sensor Type Column

To see details on which sensor types are involved, select the Source ID link to bring up the details page.

Filter Data Sources

To filter the Data Sources table, use the collapsible filter menu to narrow down the list of matching data sources by fields such as Source ID, Last Log Seen, and Sensor Type.

Filter Data Sources

Filter Data Sources

Export Data Sources as CSV

You can export the full Data Sources table or selected rows to a CSV file, based on the selected filters.

To export all of the data from Data Sources to CSV:

  1. Filter the table of data sources, if necessary.
  2. In the top right corner of the Data Sources table, select Export All as CSV.
  3. Proceed to Data Exports where the finished CSV file will be ready to download.

Tip

To export a file with all data sources, remove all filters from the table.

Export All Data Sources

Export Filtered Data Sources

To export selected data sources:

  1. Filter the table of data sources, if necessary.
  2. Select the check boxes of the data sources you want to download.
  3. In the top right corner of the Data Sources table, select Export Selected as CSV.
  4. Proceed to Data Exports where the finished CSV file will be ready to download.

Export Selected Data Sources

Export Selected Data Sources

View Data Source Health

The overview table also provides an indicator of the logging health of the data source via the Status column. The status label assigned is based on the amount of elapsed time since a log message was last seen from the device. Any device that has stopped sending data for more than 24 hours will be listed as No Data and will be included in an email summary notification sent to all users subscribed to the Data Source Notifications email preference.

Note

The Data Source Notifications email notification is disabled by default. It is recommended that all users responsible for ensuring data flow have this notification preference enabled.

Data Source Health notifications should always be investigated.

The health of a data source can be one of the following:

Note

After 30 continuous days in a No Data status, a data source will stop being displayed in the table and email notifications will cease.

If a data source is not in a Healthy state, make sure the device is online, can reach the Taegis™ XDR Collector, and then refer to the corresponding integration guide for the device type to ensure it is configured to log to the XDR Collector correctly.

Delete Data Sources

Delete one or more data sources to remove the device records from the table and stop health status email notifications enabled in your Profile Settings for the devices. This action cannot be undone.

Important

The delete action deletes the device record and does not delete or affect the telemetry received from the data source. If a deleted data source continues to send telemetry to XDR, it reappears in the Data Sources table.

Delete a Single Data Source

  1. From the Data Sources table, select the Delete icon from the Actions column for the data source you wish to delete. A confirmation modal displays.

Delete Single Data Source

Delete Single Data Source

  1. Select Done to confirm the delete action. The data source is deleted and removed from the table.

Delete Multiple Data Sources

  1. From the Data Sources table, select the checkboxes to the left of the data sources you wish to delete. A count of selected sources displays above the table.
  2. Select the Delete icon from the count of selected sources above the table. A confirmation modal displays.
  3. Select Done to confirm the delete action. The data sources are deleted and removed from the table.

Delete Multiple Data Sources

Delete Multiple Data Sources

View Data Source Details

The Data Source details page includes a summary of the data source’s current status, and other basic information. It also features a chart of its message volume by schema over the last 24 hours, and a list of sample messages generated by the data source.

To view data source details:

  1. Select the Source ID of the data source you want to see details for.

  2. The Data Sources Details panel displays.

Data Source Details

Data Source Details

Pivot Search from a Data Source

There are two ways to run a pivot search from a data source:

 

On this page: