Skip to main content
| kyberis is a streaming command. It reads indicator values — IPs, domains, URLs, hashes, emails — from the named event fields, deduplicates them, enriches them in batched Kyberis API calls (up to 50 indicators per call, never one call per event), and appends kyberis_* verdict fields to each event. Events whose target fields are empty pass through untouched. It runs on the search head only, so credentials and outbound traffic stay off the indexers. Running it requires the list_storage_passwords capability; see Permissions.

Options

Examples:

Output fields

Every processed indicator produces kyberis_ioc plus: Verdict fields are omitted when the API did not provide them. When one event contains several distinct indicators — multiple fields, or multivalue fields — kyberis_ioc and every result field become multivalue, aligned by index.

kyberis_status values

  • ok — a verdict was returned; the fields above are populated.
  • error — the API answered but could not assess this indicator, and kyberis_message carries the reason. Not cached; retried next search.
  • plan_limit — the Kyberis plan limit was hit mid-search (HTTP 402). Already-enriched events keep their results, remaining events get this status, and the search shows a warning. Not cached; retried next search.
  • transport_error — the API was unreachable, through a connection failure or a timeout after retries. The search shows a warning, and after two consecutive failed batches no further API calls are made for the rest of the search. Not cached; retried next search.
A configuration or credential problem — missing key, invalid base_url, rejected credentials — fails the search with an actionable error instead of annotating events. See Troubleshooting.

Caching

Successful results (kyberis_status=ok) are cached in the kyberis_ioc_cache KV Store collection and shared across searches, users, profiles, and the alert action. Within cache_ttl_seconds (kyberis.conf, default 86400, or 24 hours) a repeated indicator costs zero API calls.
  • Verdicts can therefore be up to cache_ttl_seconds stale. Use cache=false when freshness matters more than quota, or lower the TTL.
  • cache_ttl_seconds = 0 disables the cache entirely.
  • Expiry is lazy: expired entries are ignored on read and swept opportunistically during searches. No background jobs.
  • Cache entries are scoped to the base_url they were fetched from, so re-pointing environments refetches rather than serving foreign verdicts.
  • The cache fails soft in every direction. A missing collection, no write access, or a down KV Store degrades to uncached enrichment with a search-log warning — never a failed search.
Per-search cache statistics (kyberis cache: N hit(s), M miss(es), K write(s)) are logged to the search’s search.log.

CIM Threat Intelligence mapping

Qualifying verdicts additionally gain the field names of the Threat_Activity dataset of the Threat Intelligence data model, which ships with Enterprise Security rather than the CIM add-on: In Enterprise Security semantics an event carrying threat_* fields is a threat match, so benign verdicts must not produce them. Mapping requires kyberis_status=ok and kyberis_threat at or above cim_min_threat (kyberis.conf, default medium; set low to map every successful verdict). cim=false suppresses the mapping for one search. The kyberis_* fields are always present regardless of gating.
Search-time fields cannot carry tags, so piped | kyberis output does not itself populate the data model — only indexed events do. The alert action writes indexed events that qualify.

Cancellation

The command enriches in bounded chunks. Finalizing or cancelling a search lets the chunk in flight — at most 50 indicators — drain before the command exits. Results already fetched are kept and cached, and no further API calls are made.

| kyberischeck

A generating command that resolves a credential profile into a ready API client and reports the effective configuration in one result row, without calling the Kyberis API and without ever emitting the key. See Credential setup for the output fields.