Getting to Know Chronicle: Outcomes - Risk Score, Conditional Logic and Mathematical Operators

We are covering a lot of ground today, as we take a look at risk score, conditional logic and mathematical operators, all of which can be added to the outcome section of a YARA-L rules in Chronicle SIEM.

Outcomes_ Risk Score CL Math.png

While we are applying the concepts of conditional logic and mathematical operations to a risk score today, it's important to understand that conditional logic (if then else statements) and mathematical operators are not limited to calculating risk score. Risk score is considered a special variable as its value is carried into alert queues and are available to analysts and playbooks.

Follow along in the video below to see how conditional logic and mathematical operators can be used to create a risk score within the outcome section of a YARA-L rule.

Remember that conditional logic can be used throughout outcomes, not just in the risk score. The syntax is straightforward; if <field> operator <value>, then x, else y. Mathematical operators include addition, subtraction, multiplication, division and modulus and can be used throughout the outcome section. There are some additional uses for mathematical operators beyond what we covered today that we will circle back to in time.

Outcomes_ Risk Score CL Math (1).png

Check out these additional resources with more information and learning opportunities:

Contributors
Version history
Last update:
‎02-22-2024 07:21 AM
Updated by: