Warehouse Analytics: Job Definition View

Document created by RSA Information Design and Development on Sep 11, 2017Last modified by RSA Information Design and Development on Oct 16, 2017
Version 4Show Document
  • View in full screen mode
 

Job Definition View

Note: Warehouse Analytics is not supported in Netwitness Suite 11.0 release.

In the Job Definition view you can create and manage new jobs. You must first import the Warehouse Analytics models from the RSA Live and define and schedule jobs for generating reports. You can include whitelists in Warehouse Analytics jobs to ignore non-suspicious domains while processing data for reports.

Workflow

This workflow is overview of the entire procedure to access Warehouse data and generate reports for analyzing and investigating indicators of compromise (IOC).

What do you want to do?

                                      
Role I want to ...Show me how
AdministratorAccess Warehouse DataConfigure Reporting Engine to Access Warehouse Data
Administrator Configure Reports for Warehouse Data

Create Jobs and Run Scheduled Jobs* in

Configure Reports for Warehouse Analytics
AdministratorManage a Warehouse Analytics Job

Manage Reports for Warehouse Analytics

Threat AnalystView and analyze a Report

Analyze Warehouse Analytics Reports

Threat AnalystInvestigate a ReportInvestigation from Warehouse Analytics Reports

*You can complete these tasks here (that is in the Job Definition view).

Related Topics

Quick View

The following figure shows the Job Definition view.

Job Defination view

The Job Definition view consists of the following sections:

             
1Job Definition Panel
2Advanced Options Panel

Job Definition Panel

The Job Definition panel allows you to define and schedule Warehouse Analytics jobs.

The following table describes the fields on the Job Definition panel.

                                  
Field    Description
Enable

Enables the report schedules and runs the report.

Name  

Identifies and labels the report.

Model

Identifies and labels the Warehouse Analytics model or jar file to be imported. This option is visible only when you create or edit Jobs.

Note: Depending on the model you select, the values are pre-populated in the Advanced Options panel.

WarehouseIdentifies and labels the Warehouse data source. (For example, MapR or Horton Works).
On    Past - Allows you to specify the number of days on which the query is run.
Range (Specific) - Allows you to select a date range From and To for which the query is run.

Advanced Options Panel

The Advanced Options panel allows you to define or customize several parameters such as:
Model, HDFS, MapR, Sandbox JVM of the Warehouse Analytics job.

The following table lists the fields in the Advanced Options panel.

                                                                       
Field    Description
Model Parameters

Warehouse Analytics model or job parameter. You can include Whitelists, for more information, see the Using a Whitelists in Warehouse Analytics Jobs section in Configure Reports for Warehouse Analytics.

Note: Depending on the model selected, you get a list of white listed domains in the Model Parameters section. The domains are listed but with the score of -1. For instance, a domain by name example.com, does not appear in the list of suspicious domains.

    NameIdentifies and labels the model parameter.
    ValueDefines value of the model parameter.
Displays the List Selection window. For more information, see the List View topic in the Reporting Guide.
HDFS ParametersHDFS config parameters.
    NameIdentifies and labels the Hadoop Distributed File System (HDFS) parameter.
    ValueDefines value of the HDFS parameter.
MapR ParametersDescribes Hadoop or MapR configuration parameters.
    NameIdentifies and labels the MapR parameter.
    ValueDefines value of the MapR parameter.
Sandbox JVM ParametersJVM parameters or system parameters for JVM executing the Warehouse Analytics model.
    NameIdentifies and labels the Sandbox JVM parameter.
    ValueDefines value of the Sandbox JVM parameter.
SaveSchedules the job.
ResetResets the scheduled job.
You are here
Table of Contents > Warehouse Analytics References > Job Definition View

Attachments

    Outcomes