Documentation Index

Fetch the complete documentation index at: https://docs.databee.buzz/llms.txt

Use this file to discover all available pages before exploring further.

Collections

Prev Next

DataBee collections helps your security team work smarter by enabling you to use collections of selected information, like a list of 100 IP addresses or specific email addresses, in your operations. You can use these custom lists to quickly spot threats, reduce false alarms by suppressing alerts for known safe activities, highlight risky users, or tune down unnecessary alerts from service accounts. Simply upload a file with your values or use a DataBee query to create a list, give it a name (alias), and then use that alias across various DataBee features like Detection Chains, Suppression Lists, and Search, saving you time and effort.

Creating a Collection

From the top navigation bar, click on Data and from the dropdown menu, select Collections.

The "Collections" page displays a list of all existing collections. To create a new collection, click on the Add New Collection button.

This takes you to the “Create Collection” page. Follow the steps below and fill in the following fields with suitable data.

Step 1: Define

  • Name: enter a unique name for your collection.

  • Type: select the type of data this collection will hold from the drop-down list (e.g., User, Device, Application, IP, Hash or String).

  • Description: provide a brief description of the collection's purpose.

Click Next to continue.

Step 2: Add Content

  • Source Content From: choose how you want to add content to your collection- either by using the DataBee Search and filter option or by importing a CSV or Excel file.

Select the Use DataBee Search option to populate your collection using results from DataBee search against a data lake. You can click on the From Saved Search button and select a saved search query from the list.

  • Schema: select the relevant schema from the list.

  • Create Collection from: select the relevant event or entity type from the list.

  • Search Parameters: use the filter options to refine the content for your collection. Click Reset to clear all default parameters, and use Add Parameter to select and apply filters individually.

  • Automatic Updates: choose Yes if you want your collection to automatically update with new matching data as it's ingested. This means you won't need to manually re-create or update it. This is helpful for dynamic environments like watching for new users tagged as “terminated” based on real-time logs. Choose No if you want the collection to remain static after creation. It won't pull in new data unless you manually update or re-create it. This is helpful for fixed datasets such as a list of users affected by a phishing campaign in June 2024.

Import From File

Select the Import From File option to upload content directly from a file.

Click on Attach File to upload your collection content. Supported formats are CSV and Excel.

Click Next to proceed.

Step 3: Review

Review the total content you've selected for your collection. You can also use the search option on this page to confirm that all desired entities are included.

The image below displays a list of user collection.

Here is an IP collection shown in the same review step.

Click Save to finalize and add your collection to the Collections table. Once saved, you can view your collection displayed on the “Collections” page with information about the collection type, name, description, suppressions, detection chains, and modification information.

Manage Collections

Once you've created collections, you can easily manage them from the "Collections" page.

Under the ‘ACTIONS’ column for each collection, you'll find two icons:

  • View Collection: Click the info (i) icon to see the full details of a specific collection. Here you can view, edit, delete, and update the collection details, including adding new items or modifying existing ones, and then save your changes.

    From this page you can add items, remove items, or replace the collection’s contents entirely. See Viewing and Editing a Collection below.

    Note:

    The ability to add or delete items with view collection is available only for file-based collections. Query-based collections do not support this functionality.

  • Delete Collection: Click the trash can icon to remove an individual collection. A confirmation dialog will appear; click Yes to proceed.

Deleting Multiple Collections

To delete more than one collection at once:

Select the checkboxes on the left side of each collection you wish to delete. Click the Delete Collections button. A confirmation dialog box will appear; click Yes to proceed with the deletion.

Viewing and Editing a Collection

Selecting the info (i) icon opens the collection on its own page. The header shows the collection name, who created it and when, when it was last updated, and the Reports, Suppressions, and Detection Chains that reference the collection. Check these before you make a change, so you know what the change will affect.

Below the header are two cards:

  • Definition — the collection’s Name, Type, Description, Source Content From, Create Collection From, Search Parameters, and Automatic Updates. These fields can be edited in place.

  • Total Items — a searchable, paginated list of everything currently in the collection. Search filters the whole collection, not only the page you are viewing.

Adding and Removing Items

The Total Items card has three controls for changing what the collection contains:

  • Add — enter items directly, separated by commas.

  • Import — upload a CSV or Excel file containing the items to add.

  • Delete — select rows using their checkboxes, then select Delete to remove all of them at once. To remove a single item, use the trash icon on its row.

Add and Import both show the new items for review and validation before they are applied, so you can correct anything that fails validation. Items that are already in the collection are skipped rather than added twice.

Note:

Your changes are not applied until you select Save Changes at the bottom of the Total Items card. If you leave the page before saving, the items you added or removed are discarded.

Replacing a Collection’s Content

Adding and importing items leaves the existing content in place. To replace the contents entirely, open the Definition card and upload a new file under Source Content From. This discards every item currently in the collection and replaces it with the contents of the file.

Warning:

Replacing a collection’s content cannot be undone, and the collection may be in use by reports, suppressions, and detection chains. Before you upload a replacement file, use the download link in the Definition card to export the current items so that you keep a copy.

Filter Collections

You can easily narrow down the list of collections displayed by applying filters.

Use existing parameters like Type, Name, or Description at the top of the page. To add more filter options, select additional parameters from the Add Parameter dropdown list.

Click the Apply button to update the table and show only the collections that match your filters.

To remove all filters and view the complete list of collections again, click the Reset button.

Using a Collection

Collections are intended to simplify taking actions on groups of items. They can be used in Searches, Saved Searches, Detection Chains, and Suppressions to accomplish a variety of use cases.

Searches

Collections can be used within the Search page to simplify operations and use of the DataBee platform. They can be used to reduce the level of effort to input a list of items into our search experience. They can be used to create shared definitions in the team and leverage during investigations. Available Collections will appear in the filter options for relevant OCSF fields based on the Collection Type.

Type

OCSF Fields

Example Values

User

DataBee User ID

4232,1231

Device

DataBee Device ID

432,121

Application

DataBee Application ID

32,121

Hash

Hash.value

a606bb931c5ec8dc17755b6355b37a70c1701e01cf500e447834ee26069bf588

IP

IP, X-Forwarded-For, X-Originating-IP

32.121.12.3

String

All String Type fields

List of email accounts, domains, urls, commands, etc.

Saved Searches

Collections can be used in Saved Searches for repeated use in workflows.

Save as Default

Collections can be used in the Default view that is presented when navigating to the Search Page to align to the customized needs of the user.

Detection Chains

Collections can be used within the Links of a Detection Chain to automate the management of lists of things to take action on. Each Type of Collection opens the door to automating security operations tasks:

  • User Collections: Create Collections of high-risk employees that can be automatically updated based on DataBee Search criteria to elevate severity and kick off investigations:  

    • Administrator Accounts

    • Executives

    • Recently Resigned Employees

  • Device Collections: Create Collections of mission critical assets that can be automatically updated based on DataBee Search criteria to elevate severity and kick off investigations:

    • Cyber Risk Required Assets, such as PCI

    • Externally facing production assets

    • Executives’ devices

  • Application Collections: Create Collections of mission critical applications that can be automatically updated based on DataBee Search criteria to elevate severity and kick off investigations:

    • Cyber Risk Required Applications, such as PCI

    • Externally facing production applications

    • Security controls and tools

  • Hashes Collections: Upload a Collections of hashes to hunt for specific threat types:

    • Known Threat Actor’s malicious hashes based on the latest threat blog

    • List of hashes related exploiting know software in the environment

  • IP Collections: Upload a Collections of IP either internal or external to:

    • Elevate severity for externally facing IP space

    • Hunt for HTTP activity to a list of IPs used in the latest threat intel report

  • String Collections: Upload a Collection of Strings to look for exact text matches and unlock uses cases like:

    • Hunt for process commands associated with known threat activity

    • Elevate severity for phishing attempts sent to shared email accounts

For example, to elevate the severity of Detection Findings for high risk Collections, create a new detection chain with the desired Severity level to increase to.

Navigate to the Links section in the “Create Detection Chain” page. From the ‘Create Link For’ field, select Detection Finding from the dropdown. From the ‘Add Parameter’ filter dropdown select ‘DataBee User ID’ or ‘DataBee Device ID’ based on the collection desired. Set the ‘In’ operator to include the name of your collection. This will be in the format of name(%unique_identifier%). Update the ‘Search Parameters’ to include other desired filters such as filtering on the security tool source or severities to upgrade. Once completed, click Add/ Update Link, and then click Save Chain to apply the changes.

Collections will appear in the format of %unique_identifier% when used in a Detection Chain Link.

Suppressions

Collections can be used within Suppressions to quiet down the noise for collections of users, devices, or strings:

  • User Collections: Create Collections of accounts that can be automatically updated based on DataBee Search criteria to reduce the severity for normal business operations such as:  

    • Service Accounts that run updates on a schedule and trigger false positives consistently during the upgrade window

    • IT Support accounts that trigger a set of detections during common troubleshooting activities

  • Device Collections: Upload Collections of devices to reduce the severity for normal business operations such as:

    • Guest Wifi Activity

    • Honeypot Activity

  • String Collections: Upload a list of known “Analytics Names” or “Rule UIDs” to reduce the severity for normal business operations.

Copyright © 2026 DataBee®, A Comcast Company.
DataBee® is a registered trademark of Comcast.