Investigate: Manage Column Groups Dialog

Document created by RSA Information Design and Development on Sep 18, 2017Last modified by RSA Information Design and Development on Sep 11, 2018
Version 15Show Document
  • View in full screen mode

You can customize the way data is displayed by defining the meta to display in a column, the position of the column in the grid, and the default width of the column. In the Manage Column Groups dialog, you can add, delete, import, export, and edit column groups to display specific meta keys. At fresh installation, out-of-the-box (OOTB) column groups are available for use in the Manage Column Groups dialog. The OOTB column groups are prefixed with RSA for identification and can be duplicated but cannot be edited or deleted. You can also create custom column groups.

To access this dialog, go to INVESTIGATE > Events and in the View drop-down list select Manage Column Groups. The View option is named for the current value, for example, Detail View, List View, Log View, or the currently selected column group.This is the Custom Column Groups drop-down

the Custom Column Groups drop-down, showing OOTB groups for Version 11.2 and later


high-level Investigate workflow with Browse Raw Events and associated actions highlighted

What do you want to do?

User RoleI want to ...Show me how
Threat Hunter

browse event metadata

Begin an Investigation in the Navigate or Events View

Threat Hunter

browse raw events

Begin an Investigation in the Navigate or Events View

Threat Hunter

analyze raw events and metadata

Begin an Investigation in the Event Analysis View

Threat Hunterinvestigate endpoints (Version 11.1)Investigate Hosts

Threat Hunter

find suspicious endpoint files (Version 11.1)

Investigate Files

Threat Hunterscan files and events for malwareConducting Malware Analysis

Incident Responder

triage an incident in Investigate

NetWitness Respond User Guide

Threat Hunter configure column groups Manage Column Groups in the Events View

*You can perform this task in the current view.

Related Topics

Quick Look

the Manage Column Groups dialog

The Manage Column Groups dialog has two panels: Groups and Settings.

At the bottom of this dialog are four buttons: Close, Cancel, Save, and Save and Apply. The following table provides descriptions of these buttons.

CloseCloses the dialog without saving.
CancelCancels all unsaved changes.
SaveSaves all changes without closing the dialog.
Save and ApplySaves and applies all changes immediately, closing the dialog.

Groups Panel

The left panel is the Groups panel. This is where you can add, delete, import, or export column groups. At the top of the panel is a toolbar which provides actions. Below the toolbar is a list of added column groups, where you can select one or more groups.

The following table lists the actions in the toolbar.

Add icon Adds a column group. Clicking this button highlights the Settings panel on the right, where you can name the column group and add or delete meta keys. At least one meta key is required to add a group.
Delete icon Deletes a column group. A confirmation dialog is displayed before the selected group is deleted.
Import icon Displays the Import Column Groups dialog, where you can select a file to upload.
Export icon Exports one or more selected groups to your computer.

Settings Panel

The right panel is the Settings panel. This is where you can create and edit column groups. This panel contains the Name field, a toolbar, and a grid.

The following table describes the features of the Settings panel.

NameThe name of the selected column group.
Add icon Adds a new row to the list of meta keys, where you can open a drop-down menu to select a new meta key.
Delete icon Deletes one or more selected meta keys. Displays a confirmation dialog before deleting.
ResetReturns column group to its most recently saved settings.
Meta KeyLists the meta keys added to the selected column group.
Display NameLists the names of the meta keys as they will be displayed in the Events view.
WidthSpecifies the width of each meta key's column. The width can be set between 10 and 1000. The default width is 100.
You are here
Table of Contents > Investigate Reference Materials > Manage Column Groups Dialog