RunReveal Glossary
A glossary of terms used throughout the RunReveal platform, documentation, and terms related to security logs and detections.
actorMap of who performed an event, including email. UEBA baselines include only events where actor email is set
Agent SchedulesThe schedule an Agent runs on. See Agents.
Agent SkillsWorkspace instruction sets that agents and MCP clients load on demand. Unlike prompts, a skill takes no runtime arguments
AgentsAI automations that run on a schedule, query workspace data with tools, and deliver findings to notification channels
AI TriageA per-detection setting that opens an investigation and runs an agent when an alert fires
AlertsDetection queries that have executed and triggered notifications to configured channels
API TokenAPI Tokens are used to authenticate with the RunReveal API when you are not logged in as a specific user. They are associated with the workspace they were created in and not any particular user.
ArtifactsSelf-contained pieces of content referenced throughout AI chat conversations
Audit LogsRunReveal's own record of API and user actions in a workspace, queryable like other logs
AWS BedrockAmazon's managed service for building AI applications with foundation models from various providers
BackfillProcess of ingesting historical log data from object storage that was collected before connecting to RunReveal
BYOC (Bring Your Own Cloud)Deployment model allowing customers to run RunReveal infrastructure in their own cloud environment
BYODB (Bring Your Own Database)A workspace whose queryable logs live in customer-owned ClickHouse. Distinct from BYOC, which runs RunReveal infrastructure in the customer's cloud
CategoriesTags used for organizing and grouping detection queries
ChatGPT (OpenAI)Conversational AI model developed by OpenAI, available for integration with RunReveal's AI chat features
Claude (Anthropic)AI assistant developed by Anthropic, available for integration with RunReveal's Native AI Chat functionality
CLIThe runreveal command-line client for the API, detection as code, and MCP. Separate from reveald, which forwards logs
ClickHouseOpen-source columnar database management system used by RunReveal for log storage and analytics
Custom DetectionsUser-created detection rules with custom SQL queries (as opposed to managed detections)
Custom ViewsVirtual tables that extract columns from stored logs, or from external files, at query time without rewriting the underlying events
Dashboard LayoutsCustomizable arrangements of graphs and panels for visualizing security data and metrics
Data ModelRunReveal's normalized schema structure for standardizing log data across all sources
Data TypesClassification system for different kinds of data fields including strings, numbers, timestamps, and booleans used in log processing
Default PipelineThe pipeline unmatched events use. Its destination step writes to the workspace ClickHouse used by Explorer and detections
DestinationsWhere pipeline destination steps write events. A destination can be the workspace ClickHouse, another ClickHouse cluster, or object storage
Detection as CodeGit-based workflows for version-controlling, managing, and deploying detection rules
Detection NotesAuthor guidance stored on a detection and passed to the triage agent. Separate from notes on an investigation
DetectionsRules that identify threats. Query detections run SQL on a schedule. Sigma streaming detections match each event as it is ingested
DiscordChat platform integration for receiving detection alerts and notifications via webhook
DroppingA pipeline step that permanently discards matching events before storage. Unlike Filters, a Drop step is local to one pipeline
EnrichmentsProcess of augmenting log events with supplemental data using pattern matching and external sources
eventTimeWhen the source says the event happened. receivedAt is when RunReveal ingested it
ExploreThe log query interface, labeled Explorer in the sidebar. Query with SQL, PQL, or natural language, pick a time range, and view results
ExplorerSidebar name for the log query interface. Documentation also calls this Explore
External MCPAn MCP server the workspace connects so chats and agents can call another product's tools. Separate from RunReveal's own MCP server
Federated SearchA custom view that queries an external S3-compatible bucket at query time. The files stay in the bucket and are not ingested
FilteringReusable regex rules that drop matching events before they are stored. Filters can apply globally or be attached to a pipeline. See Dropping for the pipeline-local step
FlagsBoolean configuration options and feature toggles used to control system behavior and enable specific functionality
ForwardersHost-side shippers that send events to a RunReveal webhook source, including reveald, Fluent Bit, Vector, Logstash, OTLP, and the Datadog forwarder
GCS (Google Cloud Storage)Google's object storage service used for log ingestion and data storage
Gemini (Google)Google's family of large language models available for integration with RunReveal's AI-powered features
Google ChatGoogle's team messaging platform integration for receiving detection alerts and notifications via webhook
GraphsVisual representations of query results displayed as charts, time series, bar graphs, or other visualization types
Group AlertsWhen enabled, every alert from one detection run is attached to a single investigation and one triage run
Health ChecksAutomated monitoring of data source volume and connectivity every 15 minutes
Important FieldsColumns a detection author marks as the first fields an investigator should read
IndicatorsStructured entities on an investigation, such as an IP, user, domain, or hash, that other investigations and the triage agent can search for
InvestigationsSecurity investigation workflow for tracking and documenting incident analysis, including artifacts, status, and collaboration
JSONJavaScript Object Notation, a lightweight data-interchange format commonly used for log data and API communication
LinearProject management platform integration for automatically creating issues when detections trigger
Logs APIRESTful API endpoint for programmatically querying and retrieving log data
Managed DetectionsPre-built, out-of-the-box detection rules that are read-only and maintained by RunReveal
Managed EnrichmentsEnrichment rules RunReveal maintains. Custom enrichments are rules the workspace authors
MaskingA pipeline step that redacts, hashes, or partially masks a field before the event is stored
MCP (Model Context Protocol)Protocol standard for connecting AI assistants and language models to RunReveal data and services
MITRE ATT&CKGlobally accessible knowledge base and framework for categorizing adversary tactics and techniques
Native AI ChatBuilt-in AI investigation agent for analyzing security data through conversational queries
Normalized SchemaThe standard field structure applied to every log. See Data Model for the column list
Notification ChannelsConfigured destinations for alert delivery including Email, Slack, PagerDuty, Jira, Webhooks, and Tines
Notification TemplatesCustomizable message formats for alert content and styling
Object StorageCloud storage services including AWS S3, Azure Blob Storage, Google Cloud Storage, and Cloudflare R2 for log ingestion
OCSFThe Open Cybersecurity Schema Framework. RunReveal uses its security categories as the second tag on a detection
On-PremA deployment of RunReveal in the customer's own environment, outside the shared RunReveal cloud
OrganizationTop-level administrative entity that contains workspaces, manages billing, and controls SSO settings
ParametersDynamic variables passed to detection queries at execution time for customization
PipelinesSequence of data processors for transforming, parsing, and normalizing log data
PlansWorkspace tier (free, pro, or enterprise) that decides which sources and features are available
PollingSource ingestion method that uses API calls on a 60-second timer to collect data
PQL (Pipeline Query Language)RunReveal's domain-specific query language as an alternative to SQL for data queries
PreconditionsConditions that decide which events a topic or pipeline step applies to
ProcessorsIn reveald, a processor wraps a source and parses events on the host before they are shipped. Pipeline steps such as transform, mask, and filter run inside RunReveal and are separate
PromptsReusable instruction templates, with optional arguments, for AI chat and agents
Query DetectionsScheduled SQL detections. Sigma streaming detections match each event during ingestion and are not on a schedule
Query HistoryRecord of previously executed queries including SQL, PQL, and AI-generated queries with their results and execution times
rawLogDatabase field containing the original, unparsed log data as received from the source
RBAC (Role-Based Access Control)Permission and access management system for controlling user capabilities in RunReveal
receivedAtCritical timestamp field indicating when log data was received and ingested by RunReveal
RegexRegular expressions used for pattern matching and text processing in log parsing, filtering, and enrichment operations
ReportsLegacy scheduled summaries. The app has no reports page. Use Agents for scheduled analysis. Audit events for reports still exist
revealdRunReveal's log forwarder. It reads local sources, can process them on the host, and ships events to RunReveal. The command-line client is the CLI
Risk ScoreNumeric value from 0-100 indicating the potential impact or severity of a detection finding
RRQ (RunReveal Query)Query execution engine specifically designed for BYOC (Bring Your Own Cloud) environments
RRSCH (RunReveal Scheduler)Detection scheduling and execution component for BYOC (Bring Your Own Cloud) deployments
RulesConditional logic and criteria for enrichment processes that add data to log events
S3 (Simple Storage Service)Amazon Web Services object storage service commonly used for log data ingestion
SamplingA pipeline step that keeps a percentage of matching events to reduce volume
Saved QueriesStored and reusable SQL queries that can be quickly accessed and executed from the Explore interface
Schedule TypesConfiguration options that determine when and how frequently detections execute
scheduled_query_runsDatabase table containing historical records of detection execution and results
SeverityClassification levels for detection importance including low, medium, high, and critical
Sigma StreamingReal-time detection capability using the open-source Sigma rule format for threat detection
SigmaLiteOpen-source library developed by RunReveal for parsing and processing Sigma detection rules
SignalsDetection results and findings that have no notification channels configured for alerting
SilencingTemporarily muting detections or health checks for a specified duration to prevent alert fatigue during maintenance or known issues
Slack BotThe RunReveal Slack app for asking questions in Slack. Distinct from a Slack notification channel that receives alerts
SOAR (Security Orchestration, Automation and Response)Integration capability for automated security response and workflow orchestration
Source TypesPredefined categories of log sources such as CloudTrail, Okta, GitHub, Slack, and others
SourcesData collection integrations and connectors from various security tools, cloud services, and business applications
sourceTTLHow many days a stored event is retained in ClickHouse. The Set TTL pipeline step writes it. Unset events keep the default of 550 days
SQL (Structured Query Language)Standard programming language for managing and querying relational databases, supported by RunReveal
SSO (Single Sign-On)Enterprise authentication method allowing users to access RunReveal using their organization's identity provider
StreamingReal-time detection during ingestion. See Sigma Streaming
Structured WebhookA webhook source that expects events already shaped like the normalized log. A generic webhook stores the body as rawLog for later transforms
SubscriptionsConfiguration linking managed detections to notification channels with customizable templates
TopicsRouting rules that select which events enter a pipeline. Evaluated top to bottom. Unmatched events use the default pipeline
TransformsData processing pipeline that converts raw log formats into RunReveal's normalized schema
UEBAPer-actor behavior baselines built from events that include an actor email. There is no separate enable switch
WebhookAn HTTP callback. As a source, a unique URL receives events. As a notification channel, RunReveal posts alerts to a URL you provide. See Structured Webhook
WorkspaceOrganizational unit that groups sources, detections, users, and configurations together