All Apps and Add-ons

Symantec Datasets - Lookup

018Porta4
New Member

Good Day,

Perhaps one of you may be able to provide some clarity in regard to a Symantec Datasets – Lookup.

In my environment, the symantec_ep_malware_category_lookup contains 18,169 results. This lookup contains a handful of fields, the field in question is: riskLevel. The 18,169 results are divided into three levels: Low, Very Low, and Moderate.

The question: Why are there no results with a riskLevel of High, Very High, or Critical? I am misunderstanding the idea of this lookup?

Question 2: Anyone able to point me to documentation where I can better research for myself?

Thank you in advance.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In November, the Splunk Threat Research Team had one release of new security content via the Enterprise ...

Index This | Divide 100 by half. What do you get?

November 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

❄️ Celebrate the season with our December lineup of Community Office Hours, Tech Talks, and Webinars! ...