Investigate: Manage Column Groups Dialog

Document created by RSA Information Design and Development on Sep 18, 2017Last modified by RSA Information Design and Development on Oct 24, 2017
Version 8Show Document
  • View in full screen mode
 

You can customize the way data is displayed by defining the meta to display in a column, the position of the column in the grid, and the default width of the column. In the Manage Column Groups dialog, you can add, delete, import, export, and edit column groups to display specific meta keys. At fresh installation, out-of-the-box (OOTB) column groups are available for use in the Manage Column Groups dialog. The OOTB column groups are prefixed with RSA for identification and can be duplicated but cannot be edited or deleted. You can also create custom column groups.

To access this dialog, go to INVESTIGATE > Events view and in the View drop-down list select Manage Column Groups. The View option is named for the current value, for example, Detail View, List View, Log View, or the currently selected column group.
This is the Custom Column Groups drop-down

Workflow

the Investigate workflow, with View Query Results highlighted

What do you want to do?

                                                
User RoleI want to ...Documentation

Threat Hunter

column groups*

Manage Column Groups in the Events View.

Threat Hunter

submit queryBeginning an Investigation of a Service or Collection
Threat Hunterview query results* Conducting an Investigation

Threat Hunter

reconstruct an event

Reconstruct an Event

Threat Hunteranalyze an event Analyze Events in the Event Analysis View
Threat Hunterconduct malware analysisConducting Malware Analysis

Incident Responder

investigate an incident

NetWitness Respond User Guide

*You can perform this task in the current view.

Related Topics

Quick Look

This is the Manage Column Groups dialog

The Manage Column Groups dialog has two panels: Groups and Settings.

At the bottom of this dialog are four buttons: Close, Cancel, Save, and Save and Apply. The following table provides descriptions of these buttons.

                            
FeatureDescription
CloseCloses the dialog without saving.
CancelCancels all unsaved changes.
SaveSaves all changes without closing the dialog.
Save and ApplySaves and applies all changes immediately, closing the dialog.

Groups Panel

The left panel is the Groups panel. This is where you can add, delete, import, or export column groups. At the top of the panel is a toolbar which provides actions. Below the toolbar is a list of added column groups, where you can select one or more groups.

The following table lists the actions in the toolbar.

                           
ActionDescription
Add icon Adds a column group. Clicking this button highlights the Settings panel on the right, where you can name the column group and add or delete meta keys. At least one meta key is required to add a group.
Delete icon Deletes a column group. A confirmation dialog is displayed before the selected group is deleted.
Import icon Displays the Import Column Groups dialog, where you can select a file to upload.
Export icon Exports one or more selected groups to your computer.

Settings Panel

The right panel is the Settings panel. This is where you can create and edit column groups. This panel contains the Name field, a toolbar, and a grid.

The following table describes the features of the Settings panel.

                                        
FeatureDescription
NameThe name of the selected column group.
Add icon Adds a new row to the list of meta keys, where you can open a drop-down menu to select a new meta key.
Delete icon Deletes one or more selected meta keys. Displays a confirmation dialog before deleting.
ResetReturns column group to its most recently saved settings.
Meta KeyLists the meta keys added to the selected column group.
Display NameLists the names of the meta keys as they will be displayed in the Events view.
WidthSpecifies the width of each meta key's column. The width can be set between 10 and 1000. The default width is 100.
You are here
Table of Contents > Investigation Reference Materials > Manage Column Groups Dialog

Attachments

    Outcomes