Kaspersky Unified Monitoring and Analysis Platform

Resource search

You can search resources by name or tags. You can also use full-text search to search for resources by all of their fields. For resources of the Correlation rules type, you can use full-text search to search for correlators in which the rules are used. Searching by filter finds all resources that use the filter.

The search is carried out only on the latest version of the resources.

To find resources:

  1. In the KUMA web interface, in the Resources section, select the type of resources that you need.

    This opens a window opens with a table of available resources of this type.

    If you want to view all resources, in the Resources section, go to the List tab.

  2. If necessary, to toggle the search mode, click the table icon in the upper part of the resource table.

    You can search by name, tags, or full-text search in all fields of resources. By default, search by name, tags, and correlators is enabled (only for correlation rules).

    You can tell which search mode is currently enabled by the default text that is displayed in the search field.

  3. In the Search field, start typing the search text.

    The search is initiated as you type characters in the field and is case-insensitive. The table displays only those resources that satisfy the search conditions, and the number of such resources is displayed in the lower part of the table.

    For full-text search, the results are sorted in the descending order of the number of words from the search string found in the fields of a resource. KUMA searches the JSON of a resource; if another resource is specified in it, it searches the specified resource too. If the resource refers to other resources, KUMA also traverses these resources and searches in their content.

  4. If you want to reset the search result, clear the Search field or click the close_sql icon.