Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Working with RiskVision Incidents : Customizing the Transaction Viewer
Customizing the Transaction Viewer
Incidents | TRITON RiskVision | v2.1 | 02-Jun-2016
You can customize the Transaction Viewer to highlight the details you find most valuable for investigating and remediating security events.
*
*
Specify the Time period to display. The default value reflects the time span between the oldest incident in the database (by incident time) and the current day.
When you click the field to change the time period, a calendar tool is displayed. Mark the Specify start and end time check box below the calendar tool to further narrow the period displayed.
*
*
*
Specify whether or not to Show hidden incidents. Incidents created based on cloud app data that have no other threat or data loss characteristics are hidden by default.
*
Enter a string (like a threat name, user name, or IP address) in the Filter field to show only incidents that contain that string.
*
Group the data in the table by one or more fields (for example, source IP and threat name, and shown below). To do this, click on a column header (like User Name) and drag it straight up into the sorting row above the table. Repeat for each additional field that you'd like to use to group the data.
The result looks like this, with the "group by" fields appearing at the top of the table, and the data in the table grouped accordingly:
To stop using a particular field to group data, click the "x" next to the field name in the "group by" row.
*
*
*
Use the View drop-down list to select a predefined set of columns to show in the table. The default view emphasizes threat and data loss information for HTTP transactions.
*
Use the Show/Hide Columns drop-down list to customize which columns appear in the table.
See RiskVision Transaction Viewer table columns for more information about the columns that can be displayed in the table.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Working with RiskVision Incidents : Customizing the Transaction Viewer
Copyright 2016 Forcepoint LLC. All rights reserved.