First hour checklist

From a fresh console to a first alert and a first case, in the order that works.

Work through these in order. Each step links to the page with the details.

  • Create an organization. Settings › Organizations. Even a single-company deployment needs one. Organizations
  • Enrol one endpoint. Download the installer bundle for the organization from Settings › Agents and run it on a test machine. Watch it appear on the Hosts page. Install on Windows, Install on Linux
  • Connect one non-agent source. Point a firewall or a Linux host at the syslog listener, or post a JSON event with an ingest key. Watch it land on the Logs page. Data sources
  • Enable the content pack. Detections › Import content pack. Rules arrive disabled; enable the ones for the sources you have. Content pack
  • Fire a test event. Every content-pack rule ships with a test event. Run one from the rule's page and watch the alert appear in the queue. Writing rules
  • Work the alert. Open it, read the advisory verdict if a model is configured, look at the event graph, and escalate it to a case. Alerts
  • Close the case. Add a note, complete the tasks, close. Then write a report from a template and preview it. Cases, Reports
  • Attach a playbook. Build a simple playbook (enrich, advisory verdict, triage note) in pre-stage mode and bind it to the rule you tested. Fire the test event again. Playbooks
  • Set the SLA policy. Settings › Organizations › the organization › SLA: targets per severity and the coverage window. SLA
  • Invite a customer to the portal. Only if you are a provider: enable portal access for the organization and send an invite. Inviting customers

When all ten are done you have exercised every module once. The rest of the documentation goes deeper on each.