Virus Trending

by David Schwalenberg
October 23, 2013

The LCE normalizes logs from many different types of antivirus technologies, including malware detected by the LCE Windows Client. This dashboard presents all events from the "virus" event type as a 25-day trend by detection product type, as a 1-day count by detection product, and as a 7-day trend by specific event. In addition, any virus-related events that have caused anomalies and any new types of virus events are presented as a 7-day trend by specific event. The dashboard and its components are available in the SecurityCenter 4.7 Dashboard app feed, an app store of dashboards, reports, and assets.

The dashboard requirements are:

  • SecurityCenter 4.7
  • LCE 4.2.1
  • LCE Client 4.2.0

Listed below are the included components:

Virus Trending – 25 Day / Events by Detection Product Type
This component displays line charts of the counts of “virus” type events per 24 hours over the last 25 days. Each line represents a different detection product type; text filtering on the normalized events is used to group the products by type. Multiple products may be included in a type by using the “+event” syntax to filter for multiple text strings.

Virus Trending – 1 Day / Events by Detection Product
This component displays a matrix of the counts of “virus” type events over the last 24 hours for various detection products. The matrix displays two columns of products with their associated counts.

Virus Trending – 7 Day / Events
This component displays a table of the normalized event name of each specific “virus” type event that occurred over the last 7 days, along with their associated counts and trend lines. The events are sorted by count; only the top 15 events with the highest counts are displayed.

Virus Trending – 7 Day / Statistical Events
This component displays a table of the normalized event name of each specific “stats” type event with “Virus” in the name that occurred over the last 7 days, along with their associated counts and trend lines. The events are sorted by count; only the top 15 events with the highest counts are displayed.

Virus Trending - 7 Day / First Time Seen Events
This component displays a table of the normalized event name of each specific “nbs” (never before seen) type event with “Virus” in the name that occurred over the last 7 days, along with their associated counts and trend lines. The events are sorted by count; only the top 15 events with the highest counts are displayed.