Investigate: Manage Profiles Dialog

Document created by RSA Information Design and Development on Sep 18, 2017Last modified by RSA Information Design and Development on Sep 11, 2018
Version 15Show Document
  • View in full screen mode
 

Profiles allow you to set up custom views in the Navigate view and the Events View. At fresh installation, OOTB profiles are available in the Manage Profiles dialog. The OOTB profile groups are prefixed with RSA for identification and can be duplicated but cannot be edited or deleted. In the Manage Profiles dialog, you can configure, add, delete, import, and export profiles. In Version 11.2 and later, you can organize profiles into profile groups.

To access this dialog in the Investigation > Navigate or Events view toolbar, select Profile > Manage Profiles.

What do you want to do?

                                                     
User RoleI want to ...Show me how
Threat Hunter

browse event metadata

Begin an Investigation in the Navigate or Events View

Threat Hunter

browse raw events

Begin an Investigation in the Navigate or Events View

Threat Hunter

analyze raw events and metadata

Begin an Investigation in the Event Analysis View

Threat Hunterinvestigate endpoints (Version 11.1)Investigate Hosts

Threat Hunter

find suspicious endpoint files (Version 11.1)

Investigate Files

Threat Hunterscan files and events for malwareConducting Malware Analysis

Incident Responder

triage an incident in Investigate

NetWitness Respond User Guide

Threat Hunter configure profiles for the Navigate view or Events view*Use Profiles to Encapsulate Custom Views

*You can perform this task in the current view.

Related Topics

Quick Look

This is an example of the Manage Profiles dialog showing several profile groups.

the Manage Profiles dialog showing several Profile Groups (Version 11.2 and later)

The Manage Profiles dialog has two panels. At the bottom of the dialog there is a row of buttons. The following table describes the buttons.

                            
FieldDescription
CloseCloses the dialog.
CancelCancels all changes.
SaveSaves all changes.
Save and ApplySaves and applies all changes immediately.

The Profile panel on the left side of the dialog displays available profiles and allows you to add, delete, import, and export profiles. The following table describes the fields in the Profile panel.

                               
FieldDescription
Add icon Adds a new profile using the Settings panel on the right side of the Manage Profiles dialog.
Delete icon Deletes the selected profile. A confirmation dialog is displayed before the profile is deleted.
Import icon Displays the Profile Import dialog, where you can upload a file.
Export icon Exports the selected profile to your computer.
Profile NameLists all profile names.

The Settings panel on the right side of the dialog offers options to configure profiles. It can only be used when one profile is selected. The following table describes the fields in the Settings panel.

                            
FeatureDescription
Name Displays the name of the profile.
Meta Group Displays a drop-down menu listing available meta groups.
Column Group Displays a drop-down menu listing available column groups. Three groups are available by default:
  • List View
  • Detail View
  • Log View
PreQuery Defines a limiting query for filtering Investigation results. This query is used when the associated profile is activated and the preQuery applies to any queries used in the Investigation Navigate and Events views. This is an example of a preQuery:
'service=80,25,110'.
Next Topic:Navigate View
You are here
Table of Contents > Investigate Reference Materials > Manage Profiles Dialog

Attachments

    Outcomes