DataBee collections helps your security team work smarter by enabling you to use collections of selected information, like a list of 100 IP addresses or specific email addresses, in your operations. You can use these custom lists to quickly spot threats, reduce false alarms by suppressing alerts for known safe activities, highlight risky users, or tune down unnecessary alerts from service accounts. Simply upload a file with your values or use a DataBee query to create a list, give it a name (alias), and then use that alias across various DataBee features like Detection Chains, Suppression Lists, and Search, saving you time and effort.
Creating a Collection
From the top navigation bar, click on Data and from the dropdown menu, select Collections.

The "Collections" page displays a list of all existing collections. To create a new collection, click on the Add New Collection button.
.png?sv=2026-02-06&spr=https&st=2026-08-25T23%3A43%3A04Z&se=2026-08-26T00%3A01%3A04Z&sr=c&sp=r&sig=vrLVazrT%2Bs%2BHMg0lers6uiLIXgKUYFHJ08HXc6BCT%2Bs%3D)
This takes you to the “Create Collection” page. Follow the steps below and fill in the following fields with suitable data.
Step 1: Define
Name: enter a unique name for your collection.
Type: select the type of data this collection will hold from the drop-down list (e.g., User, Device, Application, IP, Hash or String).
Description: provide a brief description of the collection's purpose.
Click Next to continue.

Step 2: Add Content
Source Content From: choose how you want to add content to your collection- either by using the DataBee Search and filter option or by importing a CSV or Excel file.

Use DataBee Search
Select the Use DataBee Search option to populate your collection using results from DataBee search against a data lake. You can click on the From Saved Search button and select a saved search query from the list.
Schema: select the relevant schema from the list.
Create Collection from: select the relevant event or entity type from the list.
Search Parameters: use the filter options to refine the content for your collection. Click Reset to clear all default parameters, and use Add Parameter to select and apply filters individually.
Automatic Updates: choose Yes if you want your collection to automatically update with new matching data as it's ingested. This means you won't need to manually re-create or update it. This is helpful for dynamic environments like watching for new users tagged as “terminated” based on real-time logs. Choose No if you want the collection to remain static after creation. It won't pull in new data unless you manually update or re-create it. This is helpful for fixed datasets such as a list of users affected by a phishing campaign in June 2024.


Import From File
Select the Import From File option to upload content directly from a file.
Click on Attach File to upload your collection content. Supported formats are CSV and Excel.
Click Next to proceed.
.png?sv=2026-02-06&spr=https&st=2026-08-25T23%3A43%3A04Z&se=2026-08-26T00%3A01%3A04Z&sr=c&sp=r&sig=vrLVazrT%2Bs%2BHMg0lers6uiLIXgKUYFHJ08HXc6BCT%2Bs%3D)
Step 3: Review
Review the total content you've selected for your collection. You can also use the search option on this page to confirm that all desired entities are included.
The image below displays a list of user collection.

Here is an IP collection shown in the same review step.

Click Save to finalize and add your collection to the Collections table. Once saved, you can view your collection displayed on the “Collections” page with information about the collection type, name, description, suppressions, detection chains, and modification information.

Manage Collections
Once you've created collections, you can easily manage them from the "Collections" page.
Under the ‘ACTIONS’ column for each collection, you'll find two icons:
View Collection: Click the info (i) icon to see the full details of a specific collection. Here you can view, edit, delete, and update the collection details, including adding new items or modifying existing ones, and then save your changes.
From this page you can add items, remove items, or replace the collection’s contents entirely. See Viewing and Editing a Collection below.

Note:
The ability to add or delete items with view collection is available only for file-based collections. Query-based collections do not support this functionality.
Delete Collection: Click the trash can icon to remove an individual collection. A confirmation dialog will appear; click Yes to proceed.
Deleting Multiple Collections
To delete more than one collection at once:
Select the checkboxes on the left side of each collection you wish to delete. Click the Delete Collections button. A confirmation dialog box will appear; click Yes to proceed with the deletion.
Viewing and Editing a Collection
Selecting the info (i) icon opens the collection on its own page. The header shows the collection name, who created it and when, when it was last updated, and the Reports, Suppressions, and Detection Chains that reference the collection. Check these before you make a change, so you know what the change will affect.
Below the header are two cards:
Definition — the collection’s Name, Type, Description, Source Content From, Create Collection From, Search Parameters, and Automatic Updates. These fields can be edited in place.
Total Items — a searchable, paginated list of everything currently in the collection. Search filters the whole collection, not only the page you are viewing.
Adding and Removing Items
The Total Items card has three controls for changing what the collection contains:
Add — enter items directly, separated by commas.
Import — upload a CSV or Excel file containing the items to add.
Delete — select rows using their checkboxes, then select Delete to remove all of them at once. To remove a single item, use the trash icon on its row.
Add and Import both show the new items for review and validation before they are applied, so you can correct anything that fails validation. Items that are already in the collection are skipped rather than added twice.
Note:
Your changes are not applied until you select Save Changes at the bottom of the Total Items card. If you leave the page before saving, the items you added or removed are discarded.
Replacing a Collection’s Content
Adding and importing items leaves the existing content in place. To replace the contents entirely, open the Definition card and upload a new file under Source Content From. This discards every item currently in the collection and replaces it with the contents of the file.
Warning:
Replacing a collection’s content cannot be undone, and the collection may be in use by reports, suppressions, and detection chains. Before you upload a replacement file, use the download link in the Definition card to export the current items so that you keep a copy.
Filter Collections
You can easily narrow down the list of collections displayed by applying filters.
Use existing parameters like Type, Name, or Description at the top of the page. To add more filter options, select additional parameters from the Add Parameter dropdown list.
Click the Apply button to update the table and show only the collections that match your filters.
To remove all filters and view the complete list of collections again, click the Reset button.

Using a Collection
Collections are intended to simplify taking actions on groups of items. They can be used in Searches, Saved Searches, Detection Chains, and Suppressions to accomplish a variety of use cases.
Searches
Collections can be used within the Search page to simplify operations and use of the DataBee platform. They can be used to reduce the level of effort to input a list of items into our search experience. They can be used to create shared definitions in the team and leverage during investigations. Available Collections will appear in the filter options for relevant OCSF fields based on the Collection Type.
Type | OCSF Fields | Example Values |
|---|---|---|
User | DataBee User ID | 4232,1231 |
Device | DataBee Device ID | 432,121 |
Application | DataBee Application ID | 32,121 |
Hash | Hash.value | a606bb931c5ec8dc17755b6355b37a70c1701e01cf500e447834ee26069bf588 |
IP | IP, X-Forwarded-For, X-Originating-IP | 32.121.12.3 |
String | All String Type fields | List of email accounts, domains, urls, commands, etc. |

Saved Searches
Collections can be used in Saved Searches for repeated use in workflows.

Save as Default
Collections can be used in the Default view that is presented when navigating to the Search Page to align to the customized needs of the user.

Detection Chains
Collections can be used within the Links of a Detection Chain to automate the management of lists of things to take action on. Each Type of Collection opens the door to automating security operations tasks:
User Collections: Create Collections of high-risk employees that can be automatically updated based on DataBee Search criteria to elevate severity and kick off investigations:
Administrator Accounts
Executives
Recently Resigned Employees
Device Collections: Create Collections of mission critical assets that can be automatically updated based on DataBee Search criteria to elevate severity and kick off investigations:
Cyber Risk Required Assets, such as PCI
Externally facing production assets
Executives’ devices
Application Collections: Create Collections of mission critical applications that can be automatically updated based on DataBee Search criteria to elevate severity and kick off investigations:
Cyber Risk Required Applications, such as PCI
Externally facing production applications
Security controls and tools
Hashes Collections: Upload a Collections of hashes to hunt for specific threat types:
Known Threat Actor’s malicious hashes based on the latest threat blog
List of hashes related exploiting know software in the environment
IP Collections: Upload a Collections of IP either internal or external to:
Elevate severity for externally facing IP space
Hunt for HTTP activity to a list of IPs used in the latest threat intel report
String Collections: Upload a Collection of Strings to look for exact text matches and unlock uses cases like:
Hunt for process commands associated with known threat activity
Elevate severity for phishing attempts sent to shared email accounts
For example, to elevate the severity of Detection Findings for high risk Collections, create a new detection chain with the desired Severity level to increase to.
Navigate to the Links section in the “Create Detection Chain” page. From the ‘Create Link For’ field, select Detection Finding from the dropdown. From the ‘Add Parameter’ filter dropdown select ‘DataBee User ID’ or ‘DataBee Device ID’ based on the collection desired. Set the ‘In’ operator to include the name of your collection. This will be in the format of name(%unique_identifier%). Update the ‘Search Parameters’ to include other desired filters such as filtering on the security tool source or severities to upgrade. Once completed, click Add/ Update Link, and then click Save Chain to apply the changes.

Collections will appear in the format of %unique_identifier% when used in a Detection Chain Link.

Suppressions
Collections can be used within Suppressions to quiet down the noise for collections of users, devices, or strings:
User Collections: Create Collections of accounts that can be automatically updated based on DataBee Search criteria to reduce the severity for normal business operations such as:
Service Accounts that run updates on a schedule and trigger false positives consistently during the upgrade window
IT Support accounts that trigger a set of detections during common troubleshooting activities
Device Collections: Upload Collections of devices to reduce the severity for normal business operations such as:
Guest Wifi Activity
Honeypot Activity
String Collections: Upload a list of known “Analytics Names” or “Rule UIDs” to reduce the severity for normal business operations.
.png?sv=2026-02-06&spr=https&st=2026-08-25T23%3A43%3A04Z&se=2026-08-26T00%3A01%3A04Z&sr=c&sp=r&sig=vrLVazrT%2Bs%2BHMg0lers6uiLIXgKUYFHJ08HXc6BCT%2Bs%3D)