Label Packages

Label Packages are the collection of labelling rules. Labels are tags applied to each log message, used to characterize logs and group similar logs. For example, you can label all the login failed logs as failed. Using the label failed, you can group all the logs where the user failed to log in successfully. Labels can also be used to identify logs related to a specific threat technique or potential security attack.

../_images/LP_KB_LaP_Labels.png

Labels

Types of Label Packages:

  1. Vendor Packages: The label packages bundled with the Logpoint installation.

  2. My Packages: The label packages that you add.

You can switch between My Packages and Vendor Packages by clicking the dropdown menu at the top-left corner.

To sort the columns in ascending or descending order, move your cursor to the column you want to sort. Click the Down Arrow (DownArrow) for ascending order and the Up Arrow (UpArrow) for descending order.

../_images/LP_KB_Label_Package_Sort.png

Sorting Columns

To display Version in the UI, click the MORE dropdown, click Columns, and select Version.

../_images/LP_KB_Label_Package_Column.png

Displaying Version in the UI

Adding a Label Package

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click ADD.

  3. Enter Name and Description in Package Information.

../_images/LP_KB_LaP_Add_LabelPackages.png

Adding a Label Package

  1. Enter a Name and a Description.

  2. Click Submit. Search Labels opens, containing all the existing search labels.

  3. Click ADD to add a new label.

  4. In Label Information, enter Search Query, select Package and enter List of Labels. Labels can contain only alphanumeric characters.

../_images/LP_KB_LaP_Add_LabelPak_SearchLabel_Add.png

Adding Search Label Information

  1. In LABEL INFORMATION, enter a Search Query, select a Package and enter a List of Labels.

  2. Click Submit.

In this example, all the log messages satisfying the search query device_ip = 127.0.0.1 are labeled with ip and device_ip.

Applying Labels with Label Package

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Manage Labels (manage) icon in Actions for the specific label.

  3. Click Add.

    Switch between the My Packages and the Vendor Packages by clicking the dropdown at the top-left corner of the panel.

Applying Labels from the Search Interface

  1. Go to Search and enter the query to which you want to add the labels.

  2. Click Search.

  3. Click Add Search To.

../_images/LP_LabelPack_AddFromSearch.png
  1. Select Labelling Rule to open the Search Label.

../_images/LP_LabelPack_AddFromSearch_Add.png
  1. Select a Package, and enter a List of labels.

  2. Click Submit.

Applying Labels using Normalization Signatures

You may need to add a label to particular types of logs or the logs collected by a specific device. For example, to add a label printer to all the logs collected from the printer, you can add a label to the signature of the normalization package that is used to normalize printer logs. This will add the label to all the logs processed by that normalization package. You can also add labels while adding a normalization signature.

  1. Go to Settings >> Knowledge Base and click Normalization Packages.

  2. Click Signatures (manage) in Actions.

    ../_images/LP_LabelPack_FromNormSig_List_ViewSig.png
  3. Click Edit Signature icon in Actions.

../_images/LP_LabelPack_FromNormSig_List_Edit.png
  1. Type label in the first textbox for Key Values.

  2. Enter a list of labels in the second textbox.

../_images/LP_LabelPack_FromNormSig_Add.png
  1. Type label in the first textbox for Key Value.

  2. Enter a list of labels in the second textbox and click Submit.

Applying Labels with Labeling Rules

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

  2. Click the Manage Labels (manage) icon in Actions for the respective label.

  3. Click Add to open Search Label.

../_images/LP_LabelPack_AddFromSearch_Add.png
  1. Enter a suitable Query, a Package Name, and a List of Labels.

  2. Click Submit.

In this example, all the log messages satisfying the search query device_name = localhost are labelled with Localhost and 127.0.0.1.

Exporting Label Packages

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

  2. Select the label packages you want to export.

  3. Click EXPORT.

The selected label package will be downloaded.

Importing Label Packages

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

  2. Click IMPORT.

  3. Browse to the label package.

  4. Click Submit.

Editing a Label Package

  1. Go to Settings >> Knowledge Base from the navigation bar and click Label Packages.

  2. Click the Name of the package that to edit and update the information.

  3. Click Submit.

Activating Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Activate label package icon under Actions.

  3. To activate multiple Label Packages, select all the packages you want to activate. Click MORE and choose Activate Selected Packages.

  4. To activate all the Label Packages, click MORE and choose Activate All Packages.

    ../_images/LP_KB_Label_Package_Dlete.png

    Activating Label Packages

De-activating Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click De-activate label package icon under Actions.

  3. To deactivate multiple label packages, select all the packages you want to deactivate. Click MORE and choose Deactivate Selected Packages.

  4. To deactivate all the label packages, click MORE and choose Deactivate All Packages.

    ../_images/LP_KB_Label_Package_Dlete.png

    Deactivating Label Packages

Cloning Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click the Clone icon under Actions.

  3. To clone multiple label packages, select all the packages you want to clone. Click MORE and select Clone Selected Packages.

  4. To clone all label packages, click MORE and select Clone All Packages.

    ../_images/LP_KB_Label_Package_Dlete.png

    Cloning Label Packages

  5. Enter new names for the cloned packages.

  6. Select Replace Existing? to replace an existing package with the same name.

../_images/LP_KB_LaP_ClonePanel.png

Clone Label Package

  1. Click Clone.

Deleting Label Packages

  1. Go to Settings >> Knowledge Base and click Label Packages.

  2. Click Delete (Delete) icon under Actions.

  3. To delete multiple Label Packages, select all the packages you want to delete. Click MORE and choose Delete Selected Packages.

  4. To delete all the Label Packages, click MORE and choose Delete All Packages.

    ../_images/LP_KB_Label_Package_Dlete.png

    Deleting Label Packages

  5. Click Yes.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support