Investigate: Manage Meta Groups Dialog

Document created by RSA Information Design and Development on Sep 18, 2017Last modified by RSA Information Design and Development on Apr 3, 2018
Version 13Show Document
  • View in full screen mode
 

At fresh installation, OOTB meta groups are available in the Manage Meta Groups dialog. The OOTB meta groups are prefixed with RSA for identification and can be duplicated but cannot be edited or deleted. In the Manage Meta Groups dialog, you can add, delete, import, and export meta groups.

To access this dialog in the Investigation > Navigate view toolbar, select Meta > Manage Meta Groups

Workflow

high-level Investigate workflow with Browse Event Data and associated actions highlighted

What do you want to do?

                                                     
User RoleI want to ...11.1 Documentation
Threat Hunter

browse event metadata

Begin an Investigation in the Navigate or Events View

Threat Hunter

browse raw events

Begin an Investigation in the Navigate or Events View

Threat Hunter

analyze raw events and metadata

Begin an Investigation in the Event Analysis View

Threat Hunterinvestigate endpoints (Version 11.1)Investigate Hosts

Threat Hunter

find suspicious endpoint files (Version 11.1)

Investigate Files

Threat Hunterscan files and events for malwareConducting Malware Analysis

Incident Responder

triage an incident in Investigate

NetWitness Respond User Guide

Threat Hunter add, edit, and delete meta groups*Manage Meta Groups

*You can perform this task in the current view.

Related Topics

Quick Look

Below is an example of the dialog for Version 11.1, in which additional OOTB meta groups are available: RSA Endpoint Analysis, RSA Outbound HTTP, and RSA Outbound SSL/TLS. The Manage Meta Groups dialog has two panels. The following table describes the buttons at the bottom of the dialog.

Manage Meta Groups dialog showing default RSA meta groups for Version 11.1

                            
FeatureDescription
CloseCloses the dialog.
CancelCancels all changes.
SaveSaves all changes.
Save and ApplySaves and immediately applies all changes.

The Meta Groups panel is on the left side of the Manage Meta Groups dialog. This is where you can add, delete, import, and export meta groups.

The following table describes the features of the Meta Groups panel.

                               
FeatureDescription
Add icon Adds a meta group using the Settings panel on the right side of the Manage Meta Groups dialog.
Delete icon Deletes the selected meta group. A confirmation dialog is displayed before the meta group is deleted.
Import icon Displays the Meta Group Import dialog, where you can upload a file.
Export icon Exports the selected meta group to your computer.
Group NameLists all meta group names.

The Settings panel is on the right side of the Manage Meta Groups dialog. This is where you create and edit meta groups. Below the Name field is the Meta Keys grid.

The following table describes the features of the Settings panel.

                                        
FeatureDescription
NameDisplays the name of the selected meta group.
Add icon Displays the Available Meta Keys dialog, where you can select meta keys to add to the group.
Delete icon Deletes the selected meta keys.
Actions drop-down Displays a drop-down menu, where you can select the view for all meta keys. There are four options based on the possible values for the defaultAction property used to define a key in the custom index file for the service:
  • Hidden: These meta keys are hidden by default, and are not shown in Investigation at all.
  • Open: The values of this meta key are displayed by default.
  • Close: The values of this meta key are closed by default, and can be opened manually.
  • Auto: Reverts to the default view for meta keys as specified in the service index file.
Display NameIndicates the name that is displayed for the key in Investigation views, and is defined by the description property for the key in the custom index file for the service..
Key NameIndicates the name of the meta key as defined in the custom index file for the service.
View Indicates which view the meta key is set to. You can change this by either:
  • Clicking v in the View column header, then selecting a view in order to change all meta key views.
  • Clicking a single meta key in the View column, then opening the drop-down menu in which all available views are displayed, in order to change an individual meta key view.
You are here
Table of Contents > Investigate Reference Materials > Manage Meta Groups Dialog

Attachments

    Outcomes