Analyzing Event Notifications
Event notifications are functionally similar to a task list of the analyst's daily workflow. Events that fit precise risk criteria are flagged for further analysis.
Assumptions
This guide assumes your data has a risk_score
, and that event notification settings have been configured.
If your data does not use a risk_range
score, refer to the guide for the Events Explorer widget.
Working With Event Notifications
Two widgets are used to access event notifications. The widget selected from the following list determines the form of analysis:
Instructions for "Notifications Widgets" in this guide can be taken to apply to both the Notification widget and the Notifications Explorer widget unless explicitly indicated.
Right-click an event notification to Send to Object Details Viewer, Open in new viewer widget, or Send to another Workspace.
Drag event notifications into the following common analytical widgets to invoke their corresponding functions:
- The Object Details Viewer widget allows the user two choices:
- View the notification's detail and modify the assignee, status, priority, and addition tags.
- View the detail of the event that is associated with the notification.
- View a count and link to any collections that contain the event as an item.
- The Collections widget triggers the creation of a collection, or adds the dragged event into an existing collection.
- The Collection Details widget adds the event notification to the collection that is loaded onto the widget.
- The Map widget displays geo data (both markers and polygons) that is available for the event.
- The Link Analysis widget attempts to render any linked entities and associated links.
- The Drilldown widget displays the drilldown hierarchy of pattern solutions and output events that ultimately resulted in the publishing of the dragged event if this data is available from Authoring / HCEP.
- The Event History widget renders the history of an event (if any) in a table.
- The Risk History widget displays the history of an event's risk (if any) on a timeline chart.
Using Notifications Widgets
Notifications widgets display a real-time feed of incoming and recently updated notifications, based on a user-defined window of time. Up to 100 notifications that fit the criteria are shown. Once the notifications widget is added to a workspace, it is possible to apply filters, sort notifications, and dig deeper into the event and any underlying triggers.
Using Notification Explorer Widgets
The Notifications Explorer widget is similar to the Notifications widget, but is not constrained to a time window. Both show up to 100 event notifications, and each can be filtered to find specific entries. Each notification is color-coded based on the event notification's notification tag.
Sorting and Filtering Notifications
Notification sorting is the first step toward narrowing down results from the Notifications widget.
To sort notifications:
-
From a workspace, at the top of the Notifications or Notifications Explorer widget, click the filters dropdown icon.
-
Select the filter and filtration method.
Filters for the Notifications widget include:
Filter Description Sort By Sort the notifications on this widget by the last created/updated date, priority, risk score, or tag order priority. Tags Pick or search for a specific notification or system tags to filter by. Users Pick or search for a specific user or for the current user (me) to filter by. Time Window Pick a pre-defined time window to filter notification created at or updated at timestamps by.
Filters for the Notifications Explorer widget include:
Filter Description Filter Select filtration from among time-based fields. Date Select from a pre-defined time period. Sort by Filter by last created/uploaded/occurred at dates, priority, risk score, tag order, or assigned user. Tags Filter by either notification or system tags. Users Display event notifications based on the specified user or for the current user assigned to them (me). Status Filters notifications by ingestion status: Active, Dismissed, or Archived. Priority Filters by the notification's designated priority. Text Search Allows text string matching within an event notification's data fields. -
Click Apply Filters to apply all the selected filters, or Reset to Defaults to discard the filters.
Pinning Event Notifications
A notification disappears if it no longer fits the criteria of the event notification settings, or if it falls outside of the defined timeframe. Pin event notifications to prevent them from vanishing from the list of event notifications.
Pinning notifications only applies to the Notifications widget.
To pin a notification:
- From a workworkspace, at the top of the Notifications widget, each event is listed.
- At the right side of any event, click the pin icon to pin the event notification.
- Click the pin icon again to unpin the event notification.
Notification Time Charts
The Notifications widget contains a timeline representing the quantity of notifications generated for the associated time window.
To toggle Time Chart Mode:
- At the upper left of the Notifications widget, a circle displays a count of notifications the widget has received.
- Click the circle icon to toggle the timeline plotted value between:
- Tag, which plots lines segmented by the notification tag.
- Risk history, which plots lines segmented by risk level (low, medium, high, critical).
- User, which plots lines segmented by assigned user (the notification needs to be assigned to a user first).
- Priority, which plots segmented by the notification priority.