Investigation: Drill into Data in the Values Panel

Document created by RSA Information Design and Development on Nov 23, 2016Last modified by RSA Information Design and Development on Nov 29, 2016
Version 2Show Document
  • View in full screen mode
  

Security Analytics displays the activity and values for the selected service in the Investigation > Navigate view. To investigate data, analysts drill into data by clicking on a meta key or a meta value, which is treaty as a query. In the Values panel, each query is added to the breadcrumb data in the Values panel. This results in a breadcrumb at the top with a crumb for each query. You can edit the breadcrumb to insert or remove a query.

Drill into a Subset of the Metadata

  1. Begin an investigation so that metadata is displayed in the Navigate view.
    NavViewConc.png
  2. To drill down into the metadata, do any combination of the following:
    1. Click a meta key, for example, Source Country or Destination Country.
    2. Click a meta value, the blue text in the results. For example, Italy.
      Each time you click a meta key or meta value, the investigation query pivots to a narrowed focal point, or drill point, in the data. At each drill point, the Values panel is updated and the new drill point is displayed in the breadcrumb. Below is an example of the first breadcrumb.
      BrdCrmb.png
      This is an example of a long breadcrumb that does not fit in the toolbar. The last query that fits is followed by a drop-down menu that lists additional queries. To select a drill point within the overflow, click the overflow icon and a query in the drop-down list.
      OvrflwDP.png

Add a Query in the Breadcrumb

In the breadcrumb, you can click any of the crumbs to display the Query menu. You can insert a new query before a crumb, and append a new query to the end of breadcrumb. After each edit in the breadcrumb, Security Analytics refreshes the results.

To add a query in the breadcrumb:

  1. Click a crumb.
    The Breadcrumb menu is displayed.
    BrdCrmbMenu.png
  2. To add a query in the breadcrumb, select Append or Insert Before.
    The Create Filter dialog is displayed.
    CrtFiltDg.png
  3. Create the Query as described in Create a Custom Query.

Edit a Query in the Breadcrumb

In the breadcrumb, you can click any of the crumbs to display the Query menu. You can delete a crumb and edit a query in a crumb. After each edit in the breadcrumb, Security Analytics refreshes the results.

To work with queries in the breadcrumb:

  1. Click a crumb.
    The Breadcrumb menu is displayed.
    103SP2BCEditMenu.png
  2. To edit a query in the breadcrumb, select Edit.
    The Create dialog is displayed with the selected query open for editing.
    EditFiltIPDg.png
  3. Edit the fields as described in Create a Custom Query.

Quick Search within a Meta Key

  1. Move the mouse over a meta key section and click the magnifying glass.
    The Quick Search form, which contains a comparator and an optional operand for the search, is displayed.
    QSForm.png
  2. (Optional) If you want to close the search form, click the magnifying glass again.
  3. Select the operation from the drop-down list on the left and type the text value to search for. Then click Drill to perform the execution.
    The metadata for that meta key is used to drill down in the current metadata.

View Meta Key Information in the Navigate View

To view details about a meta key, specifically the key name, index level set for displaying the meta key, and the default view set for the meta key:

  1. Click the drop-down menu next to the meta key.
    MetKeyDD.png
  2. Select Meta Key Info.
    The Meta Key Info dialog is displayed.
  3. When finished viewing, click Closedialog.png.
  4. (Optional) To view meta names found for the meta key as a comma-separated value list, click the drop-down menu next to the meta key and select View as CSV.
    The Showing Values in CSV Format dialog is displayed.
  5. When finished viewing, click Close.
  6. (Optional) If you want to hide the results for the meta key in the current drill point, click the drop-down menu next to the meta key and click Hide Results.

Display Events Associated with a Meta Value

The Events view provides additional details for an event in two different views: Events List and Detail View.

  1. In the Navigate view, drill into metadata that is the focus of your investigation.
  2. Click the count (the number in green) next to a blue meta value.
    The Events view corresponding to the current drill point is displayed.

    The operations that you can perform in the events view are described in Examine Events.

Search for Specific Events Associated with a Meta Value

  1. In the Navigate view, drill into metadata that is the focus of your investigation (click a meta value or add a query).
  2. Type a search string in the Search box and press Enter or click Search.
    You can also select and set your search mode preferences for your searches. See Investigation - Search Options for detailed search information.
    NavViewSearchExG.png
    The Events view opens in a new tab and shows the search results. Your time range selection and drills (queries) carry forward to the Events view.  
    NavViewSearchExG2.png

View a Selected Meta Value in Live

  1. In the Navigate view, drill into metadata that is the focus of your investigation.
  2. Right-click a meta value (the text in blue).
    The Meta Value drop-down menu is displayed.
  3. To look up the meta value in Security Analytics Live, select Live Lookup.
    The Live Search view is displayed with the meta value entered in the Generated Meta Value(s) field, and ready for a search.

Refocus the Investigation in a Drill Point

  1. Right-click a meta value (the text in blue).
    The Meta Value drop-down menu is displayed.
    BlConMenInv.png
  2. Choose one of the refocus options.
    The drill is refocused according to your choice.

Look at a Specific Count in a New Tab

To view a count for a meta value in a new tab or view a Geomap of the locations for the selected meta value:

  1. Right-click a count for a meta value (the green number following the blue meta value).
    The context menu is displayed.
  2. (Optional) To open a separate investigation for the specific meta value, select Open in New Tab.
  3. (Optional) to open a geomap showing the locations where the selected meta value originated, select Geo-Map Locations in New Tab.
You are here
Table of Contents > Conduct an Investigation > Query Data in the Navigate View > Drill into Data in the Values Panel

Attachments

    Outcomes