Skip navigation
All Places > Products > RSA NetWitness Platform > RSA NetWitness Platform Online Documentation > Documents
Log in to create and rate content, and to follow, bookmark, and share content with other members.

Investigate: Query Profiles Dialogs

Document created by RSA Information Design and Development on Sep 18, 2017Last modified by RSA Information Design and Development on Jan 30, 2020
Version 18Show Document
  • View in full screen mode
 

Query profiles allow you to set up custom views in the Navigate view, Events view, and Legacy Events view based on a meta group, column group, and limiting query (see Use Query Profiles to Encapsulate Common Areas for Investigation). Built-in profiles are available when you first log in; the names begin with the RSA prefix and are grouped under Default Profiles. You cannot edit or delete built-in profiles.

You can manage built-in profiles and custom profiles in the Manage Profiles dialog, the Create Query Profile dialog and the Query Profile Details dialog.

  • The Manage Profiles dialog is for the Navigate view, the Legacy Events view (Version 11.4) , and the Events view (Version 11.3 and earlier). The Manage Profiles dialog has features that are not yet available in the Query Profile dialog: select a meta group for the profile, import and export profiles, copy and edit profiles, and organize profiles into profile groups. To access this dialog, select Profile > Manage Profiles in the Navigate or Legacy Events view toolbar.
  • The Create Query Profile dialog is for the 11.4 Events view. To access this dialog, select Query Profiles > New Query Profile in the Events view toolbar.
    example of the Query Profiles menu
  • The Query Profile Details dialog is for the 11.4 Events view. To access this dialog, select Query Profiles in the Events view toolbar, then click the edit icon (the edit icon) next to a custom profile name.

Related Topics

Quick Look - Query Profile Menu, Create Query Profile Dialog, and Query Profile Details Dialog

This section introduces the Query Profile Menu, Query Profile dialog, and the Query Profile Details dialog. The following figure is an example of the Query Profiles menu and the table describes the options. The example on the left has built-in profile highlighted so that the information icon is visible. The example on the right has a custom profile highlighted so that the edit icon is visible.

Query Profile Menu with Info Icon Query Profile Menu with Edit Icon

                         
FeatureDescription
Filter Query ProfilesFilters the list of profiles as you type text so that only profile names that contain that text are displayed.
Query Profile List The list of profiles consists of custom and built-in profiles, which are distinguished by the icons that precede the name. In the example, Email Attachment and Investigate Upgrade Profile are custom profiles. The RSA profiles are built-in profiles.
New Query Profile Displays the Create Query Profile dialog, where you can create a custom profile.

The Create Query Profile dialog, shown in the figure on the left, allows you to define a custom profile. The figure on the right illustrates the Query Profile Details dialog, in which you can edit a custom profile. The table describes the fields and options in the dialogs.

the Create Query Profile dialog Query Profile Details dialog for a custom profile

                                                   
FeatureDescription
delete icon Deletes the custom profile in the Query Profile Details dialog. This action is irreversible and applies globally; the profile is no longer available to anyone who is using the profiles on this service.
Query Profile Name Displays the name of the profile. The name must be unique and contain fewer than 64 characters. You can edit the name in a custom profile.
Column Group Displays a drop-down menu listing available column groups, with the currently selected column group from the Events list already selected. You can change the column group in a custom profile.
PreQuery Conditions Defines a limiting query for filtering Investigate results. If you had a query active in the query bar when you began to create the new profile, the active query is added to the preQuery field. In a custom profile, you can delete the prepopulated preQuery and type additional text for a text search or additional filters in the preQuery field. This query is used when the associated profile is applied and the preQuery applies to any queries used in the Navigate and Events views. This is an example of a preQuery:
'service=80,25,110'.

Close button

Closes the dialog.

Save Query ProfileFor the Create Query Profile dialog only, saves the new profile.

Reset

For the Query Profile Details dialog only, reverts the edited profile to the last saved state.

Update Query Profile

For the Query Profile Details dialog only, applies changes to an edited profile.

Select Query Profile

Applies the query profile.

Quick Look - Manage Profiles Dialog

This is an example of the Manage Profiles dialog showing several profile groups.

the Manage Profiles dialog showing several Profile Groups (Version 11.2 and later)

The Profile panel on the left side of the dialog displays available profiles and allows you to add, delete, import, and export profiles. The following table describes the fields in the Profile panel.

                                   
FieldDescription
Add icon Adds a new profile using the Settings panel on the right side of the Manage Profiles dialog.
Delete icon Deletes the selected profile. A confirmation dialog is displayed before the profile is deleted.

the Duplicate icon

Creates a copy of the selected profile.

Import icon Displays the Profile Import dialog, where you can upload a file.
Export icon Exports the selected profile to your computer.
Profile NameLists all profile names.

The Settings panel on the right side of the dialog offers options to configure profiles. It can only be used when one profile is selected. The following table describes the fields in the Settings panel.

                             
FeatureDescription
Name Displays the name of the profile.
Meta Group Displays a drop-down menu listing available meta groups.
Column Group Displays a drop-down menu listing available column groups. The OOTB column groups and these three groups are available by default:
  • List View
  • Detail View
  • Log View
PreQuery Defines a limiting query for filtering Investigate results. This query is used when the associated profile is activated and the preQuery applies to any queries used in the Navigate and Events views. This is an example of a preQuery:
'service=80,25,110'.

The following table describes the buttons.

                             
FieldDescription
CloseCloses the dialog.
CancelCancels all changes.
SaveSaves all changes.
Save and ApplySaves and applies all changes immediately.

Previous Topic:Query Dialog
You are here
Table of Contents > Investigate Reference Materials > Query Profiles Dialogs

Attachments

    Outcomes