When ransomware is detected, an AlertEvent is triggered and recorded. To view AlertEvent incidents:
- Log in to the LogRhythm NDR UI.
- Click the Hunt tab, and then click Activity.
The Activity page appears. By default, the legend graph is displayed, showing the logs and events for the past hour.
- To view the AlertEvent instances alone, click AlertEvent.
All AlertEvent-related events appear.
- To search for ransomware-related AlertEvent instances, type Ransomware in the search field and click Search.
All ransomware-related AlertEvent instances appear.
- Click the + button next to ransomware-related AlertEvent entries.
A submenu with expanded Details and JSON tabs appears.