How to Run Analyzers and Review Reports for an Observable#
This topic provides step-by-step instructions for running analyzers on an observable and reviewing analyzer reports in TheHive.
Analyzers enrich observables with detailed, contextual intelligence, generating a report with the results. The type of each observable determines which analyzers are available.
Required permissions
Only users with the manageObservable
permission can manage observables in TheHive.
Run analyzers on an observable#
Bulk run
To run analyzers on multiple observables, go to the Observables tab in a case or alert and select next to each observable you want to include. Then select Run analyzers above the list.
-
Locate the observable on which you want to run analyzers.
-
In the observable, select .
-
Select Run analyzers.
-
In the Analyzer drawer, select the analyzers you want to run.
Can't find an analyzer?
If you can't find the analyzer you need, it might not be available for this observable type. Contact someone with admin-level permissions on Cortex to change the types associated with the analyzer.
-
Select Run selected analyzers.
Review analyzer reports for an observable#
-
Locate the observable on which you ran analyzers.
-
In the observable details, move through the Reports section to select a report, or move through the Analyzers section and select any green item in the Last analysis column.
-
Optional: Import observables from reports. See Import Observables from Analyzer Reports for detailed instructions.