This topic describes the CSE UI for working with Insights.
Insights list page
To open the Insights page, click the icon to the right of the search bar at the top of the CSE UI.
By default, the Insights page presents all Insights whose Status is not “Closed”, in descending order by Event Time in a list view. If you’d like to see Insights organized by their status, click the Show Board icon near the top right corner of the page. For information about the Board view, see Board view.
This screenshot shows the Insights page in List view.
Here’s one row from the List view. The numbered definitions below correspond to the labels in the screenshot.
- Creation date and time. When the Insight was created.
- Dwell time. This is the time between when the Insight was created and when an analyst was assigned to it.
- Age. The elapsed time since the Insight was created in minutes, hours, and so on.
- Insight name. The Insight name, made up of the Insight ID, and the MITRE stage or stages associated with the Signals in the Insight.
- MITRE stage.
- Global Confidence. If sufficient data is available, a Global Confidence score for the Insight is shown.
- Assignee. The analyst assigned to the Incident.
- Severity. The severity of the Insight. The value is a function of the configured Entity Activity Score threshold for Insight generation. For more information, see Insight Severity.
- Entity. The Entity associated with the Insight.
- Signal data. This area has three bits of information:
- The count of Signals that caused the Insight to be created.
- The total count of Signals on the Insight Entity during the detection window.
- How long it's been since the last Signal fired associated with the Insight fired.
This screenshot shows the Insights page with the Signals organized as a Board. Each of the columns corresponds to an Insight Status value. (One of the Status values shown is a custom Insight Status).
The information displayed in the Board view is similar to the information in the List view.
You can switch back the List view by clicking the Show List icon, near the top right corner of the CSE UI.
You can use the Filters area near the top of the page to narrow down the Insights that appear on the Insights page. You can filter by:
- Event Time
- Custom Resolution
- Rule ID
Insight Details page
This section describes the Insight > Details page.
Insight details pane
The left pane of the Insight > Details page displays detailed information about the selected Insight. Some of the information that appears is the same as what’s in the row for an Insight on the Insights page, and is described in List view, above. The additional information that appears in the Details pane is defined below.
Signal visualization area
At the top of the Insight > Details page, you’ll see a Signal timeline that visualizes the Insight’s attached Signals, which are the Signals that caused the Insight to be created, and any Signals that have been manually added to the Insight.
- Signals.The Signals link allows you to switch back to the Signals view from the Enrichments view, described below.
- Enrichments. Click this list to view the output of any Insight Enrichment Server scripts that have enriched the Insight.
- Signal timeline. The timeline shows how spread apart each Signal in the Insight is. You can use the timeline to visualize how long these events are spread over and how frequently the Signals fire.
- Timeline controls. The arrows on the far left and right sides allow you to toggle between each Signal to show the details on each. You can also click a specific Signal on the timeline to jump to those details.
- Legend. Key to the symbols used to represent the Signals
- Rules—Signals that were triggered by Match or Chain rules.
- Anomalies—Signals that were triggered by Threshold or Aggregation rules.
- Threat intelligence—Signals that were fired by Threat Intel rules. (These are Match rules that leverage threat intel matches.)
- File Analysis—Signals that were triggered by Yara file analysis rules.
- Show Related Signals. Click this link to show Related Signals in addition to Attached Signals.
- Sort options. You can sort the Signals list by Content Type, Event Time, Created Time, Name, or Severity. Note that you can further sort by ascending or descending value.
- Add Signals. Click this option if you want to add a Signal to the Insight. You’ll be prompted with a list of Signals that have the same Entity as the current Insight (if there are any), and are not already attached to another Insight. A Signal that you add to an Insight manually is considered an Attached Signal.
Signal list area
Below the Signal timeline, you’ll see a list of Signals. By default, only attached Signals are displayed.
If you click the Show Related checkbox, the page updates and also displays any Related Signals or Related Insights
- A Related Signal is a Signal that isn’t part of the current Insight (it’s not attached), but fired on the same Entity as the current Insight’s attached Signals within 7 days of the current Insight’s attached Signals.
- A Related Insight is an Insight that a Related Signal is attached to.
Here is an example of what a Related Signal and Related Insight look like in the Signal list. Note that, to distinguish between Signals that are attached as opposed to related, an Attached Signal has a blue vertical “ornament” on the left side of the row. A Related Signal does not.