| kyberis is a streaming command. It reads indicator values — IPs, domains,
URLs, hashes, emails — from the named event fields, deduplicates them, enriches
them in batched Kyberis API calls (up to 50 indicators per call, never one call
per event), and appends kyberis_* verdict fields to each event. Events whose
target fields are empty pass through untouched. It runs on the search head only,
so credentials and outbound traffic stay off the indexers.
Running it requires the list_storage_passwords capability; see
Permissions.
Options
Examples:
Output fields
Every processed indicator produceskyberis_ioc plus:
Verdict fields are omitted when the API did not provide them. When one event
contains several distinct indicators — multiple fields, or multivalue fields —
kyberis_ioc and every result field become multivalue, aligned by index.
kyberis_status values
ok— a verdict was returned; the fields above are populated.error— the API answered but could not assess this indicator, andkyberis_messagecarries the reason. Not cached; retried next search.plan_limit— the Kyberis plan limit was hit mid-search (HTTP 402). Already-enriched events keep their results, remaining events get this status, and the search shows a warning. Not cached; retried next search.transport_error— the API was unreachable, through a connection failure or a timeout after retries. The search shows a warning, and after two consecutive failed batches no further API calls are made for the rest of the search. Not cached; retried next search.
base_url,
rejected credentials — fails the search with an actionable error instead of
annotating events. See Troubleshooting.
Caching
Successful results (kyberis_status=ok) are cached in the kyberis_ioc_cache
KV Store collection and shared across searches, users, profiles, and the alert
action. Within cache_ttl_seconds (kyberis.conf, default 86400, or 24 hours) a
repeated indicator costs zero API calls.
- Verdicts can therefore be up to
cache_ttl_secondsstale. Usecache=falsewhen freshness matters more than quota, or lower the TTL. cache_ttl_seconds = 0disables the cache entirely.- Expiry is lazy: expired entries are ignored on read and swept opportunistically during searches. No background jobs.
- Cache entries are scoped to the
base_urlthey were fetched from, so re-pointing environments refetches rather than serving foreign verdicts. - The cache fails soft in every direction. A missing collection, no write access, or a down KV Store degrades to uncached enrichment with a search-log warning — never a failed search.
kyberis cache: N hit(s), M miss(es), K write(s))
are logged to the search’s search.log.
CIM Threat Intelligence mapping
Qualifying verdicts additionally gain the field names of theThreat_Activity
dataset of the Threat Intelligence data model, which ships with Enterprise
Security rather than the CIM add-on:
In Enterprise Security semantics an event carrying
threat_* fields is a
threat match, so benign verdicts must not produce them. Mapping requires
kyberis_status=ok and kyberis_threat at or above cim_min_threat
(kyberis.conf, default medium; set low to map every successful verdict).
cim=false suppresses the mapping for one search. The kyberis_* fields are
always present regardless of gating.
Search-time fields cannot carry tags, so piped
| kyberis output does not itself
populate the data model — only indexed events do. The
alert action writes indexed events that
qualify..png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=66da6f97e851defcb12af05b800a8a27)
.png?fit=max&auto=format&n=u7saXgSwhIjXsY7P&q=85&s=37df025ce7a3cc54dd90f8edad1cf54f)