ESM: Manage Tab

Document created by RSA Information Design and Development on Jul 15, 2016Last modified by RSA Information Design and Development on Feb 27, 2017
Version 5Show Document
  • View in full screen mode
  

The Manage tab organizes event sources into groups, and displays attributes for each event source.

To access this tab, in the Security Analytics menu, select Administration > Event Sources. The Manage tab is displayed by default.

esm_manage.png

Procedures related to this tab are described in Manage Event Source Groups.

The Manage tab consists of two panels, Groups and Event Sources.

Groups Panel

The Groups Panel lists the event source groups, as well as a count of the members for each group. To see all event sources, select All from the groups list. This is an example of the Groups panel.

esm_groupTab.png

The Groups panel contains the following features.

                     
FeatureDescription
Tools

These are the standard Security Analytics icons for adding, removing, or editing groups.

Count

The count for an event source group indicates the number of event sources in that group. That is, the number of event sources that match the criteria used to define the group.

Note: The count is not dynamically updated when new event sources are added. Thus, you may need to refresh to see an updated group count.

Name

The Name column lists the identifier for each group. You can use the group names to quickly identify some of the criteria used to form the group.

For example, if you create a group that consists of Windows event sources for the Sales organization, you could name the group Windows Sales Sources.

Note: The event source group name is not editable. Once you create a group, that name exists as long as the group itself.

Event Sources Panel

The Event Sources panel displays the attributes for the event sources in the selected group. Or, if All is selected in the Groups panel, the Event Sources panel lists all event sources.

esm_esTab.png

                             
FeatureDescription
Tools

The toolbar contains the following tools:

  • Add: manually add an event source
  • Remove: remove an event source
  • Edit: Update attributes for an existing event source
  • Import / Export menu, esm_impExIcon.png: Displays a menu with the following options:
    • Import: Import event sources from a  Content Management Database (CMDB), spreadsheet, or other tool.
    • Export: Export selected event sources and their attributes in CSV format.
    • Export Group: Export the entire group that is currently selected.
Attributes Columnar display of attributes. You can choose which attributes to display.
Actions Shortcut menu for often-used commands: Edit, Delete, and Export.
Check BoxesSelect rows to use when performing tasks on multiple event sources, such as bulk editing.
Navigation Tools

At the bottom of the screen, there are items that help in navigating your group:

  • Page x of y: indicates which page you are currently displaying, and how many total pages exist for this group.
  • <<, <, > and >>: click these icons to move between pages either one at a time (< and >) or to the first (<<) or last (>>) page.
  • Page Size: use this selector to choose your page size.
  • Displaying x - y of z: quick check of which event sources are currently displayed out of the total number for the group.

Sorting

In the Event Sources panel, the list of items is presented in a sorted order. You can choose which column on which to sort. Note, however, that the sort order depends on capitalization. 

For any string column, if the values contains a mix of lower case and upper case, the upper case appear in the list before the lower case values.

For example, assume the Event Source Type column contains the following entries: Netflow, APACHE, netwitnessspectrum, ciscoasa. The sort order would be as follows:

  • APACHE
  • Netflow
  • ciscoasa
  • netwitnessspectrum
Previous Topic:Event Sources View
You are here
Table of Contents > Reference > Manage Tab

Attachments

    Outcomes