Skip to main content
Version: 5.2

Architecture and Data Flows

Conceptual Diagram

The diagram reflects the main capabilities of the module.

Data Sources

The table contains indexes and directories used in the module. The data source is the BI.ZONE EDR server.

NameSource TypeIntegration TypeData CategorySemantics
bizone-irp-alerts-*indexkafkaeventsThreat detection rule alerts
bizone-irp-other-*indexkafkaeventsPreventive threat detection rule alerts
bizone-telemetry-*indexkafkaeventsTelemetry:
1. Process monitoring and inventory
2. Inter-process communication, threads, and memory monitoring
3. File system monitoring and inventory
4. Registry monitoring and inventory
5. Network activity monitoring and inventory
6. Named pipe monitoring and inventory
7. .NET monitoring
8. User session monitoring and inventory
9. ...
bizone-server-log-*indexkafkaeventsSystem log of the BI.ZONE EDR server and connected agents
bizone-tasks-result-event-*indexkafkaeventsResult of tasks executed by the EDR module
bizone-entity-actions-*indexREST APIeventsServer audit log: authorization on the BI.ZONE EDR server, management of tasks and agents
bizone-entity-agents-*indexREST APIdirectoryServers and workstations where agents are installed
bizone-entity-agentusers-*indexREST APIdirectoryLocal users on agents
bizone-entity-alerts-*indexREST APIdirectoryAlert metadata
bizone-entity-modules-*indexREST APIdirectoryAvailable modules
bizone-entity-tasks-*indexREST APIdirectoryAvailable tasks
bizone-entity-triggers-*indexREST APIeventsRegistered triggers
bizone-entity-users-*indexREST APIdirectoryBI.ZONE EDR users
dim_bizone_hostdirectoryscheduled jobdirectoryProperties of servers and workstations where agents are installed based on bizone-entity-agents-*
dim_bizone_taskdirectoryscheduled jobdirectoryTask properties based on the bizone-entity-tasks-* index
dim_bizone_ruledirectorycsvdirectoryThreat detection rules
bizone_alert_settingdirectorymanually manageddirectoryManaging incident registration based on threat detection rule alerts
link_bizone_alert_severity_incident_severitydirectorystaticrelationshipMapping alert criticality categories to incident criticality