Query Management
The administrator can query the logs database to search for logs corresponding to specific events from specific customers. The 'Investigation' feature allows the administrators to build queries for searching specific logs, for constructing correlation rules for identifying incidents and to create custom dashboards which display the resulting data as graphical charts. Comodo NxSIEM ships with a set of predefined queries for each customer and also allows you to add custom queries for customers according to your requirements.
Refer to the following sections for
more details: