You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/cse/records-signals-entities-insights/view-manage-entities.md
+24-31Lines changed: 24 additions & 31 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,28 +47,25 @@ For a list of fields that Cloud SIEM considers entities and the entity types the
47
47
Entity names have a limit of 512 characters. If an entity's name value is 512 characters or longer, the system discards the log, and as a result, no signal is generated.
48
48
:::
49
49
50
-
## About the Entities list page
50
+
## About the entities list page
51
51
52
52
[**New UI**](/docs/get-started/sumo-logic-ui). To view entities, in the main Sumo Logic menu select **Cloud SIEM > Entities**. You can also click the **Go To...** menu at the top of the screen and select **Entities**.
53
53
54
54
[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). To view entities, click **Entities** at the top of the screen.
| a | This area shows the total number of unique entities in Cloud SIEM. |
62
-
| b | In the **Filters** area, you can filter the list of entities by activity score, hostname, IP address, username, tags, type, and suppressed. |
63
-
| c | In this area you can sort entities by activity score, name, or type. |
64
-
| d | The Import Metadata option allows you to upload a .csv file of updates to entity tags, suppression state, and criticality, as described in [Update multiple entities](#update-multiple-entities). |
65
-
| e | Shows the entity type and its value. |
66
-
| f | If an entity has the **Suppressed** indicator, that means that signals will not be fired on the entity. |
67
-
| g | The **Criticality** column shows whether a [criticality](/docs/cse/records-signals-entities-insights/entity-criticality/) has been assigned to the entity. A criticality adjusts the severity of signals for specific entities based on some risk factor or other consideration. If a criticality hasn't been assigned to an entity, the column contains "default". |
68
-
| h | The current activity score for the entity, which by default is the sum of the severities of the signals that have fired on the entity over the previous two weeks. For more information, see [Understanding entity activity scores](/docs/cse/get-started-with-cloud-siem/insight-generation-process#understanding-entity-activity-scores), in the *Insight Generation Process* topic. |
69
-
| i | The total amount of signal severity for the entity. |
70
-
71
-
If you see a link below the entity value, it’s a [tag](/docs/cse/records-signals-entities-insights/tags-insights-signals-entities-rules/). You can click it to filter entities by that tag.
60
+
| a |**Filters**. Filter the list of entities by values such as signal severity total, activity score, criticality, indicator, sensor zone, suppressed, tags, type, and value. |
61
+
| b |**Import Metadata**. Upload a .csv file of updates to entity tags, suppression state, and criticality, as described in [Update multiple entities](#update-multiple-entities). |
62
+
| c | **Checkboxes**. Select checkboxes to [update multiple entities](#update-multiple-entities).
63
+
| d |**Entity**. Displays the entity name. |
64
+
| e |**Entity Type**. Shows the entity type and its value. |
65
+
| f |**Activity Score**. The current activity score for the entity, which by default is the sum of the severities of the signals that have fired on the entity over the previous two weeks. For more information, see [Understanding entity activity scores](/docs/cse/get-started-with-cloud-siem/insight-generation-process#understanding-entity-activity-scores), in the *Insight Generation Process* topic. |
66
+
| g |**Signal Severity Total**. The total amount of signal severity for the entity. |
67
+
| h |**Suppressed Lists**. If an entity is on a suppressed list, that means that signals will not be fired on the entity. |
68
+
| i |**Criticality**. Shows whether a [criticality](/docs/cse/records-signals-entities-insights/entity-criticality/) has been assigned to the entity. A criticality adjusts the severity of signals for specific entities based on some risk factor or other consideration. If a criticality hasn't been assigned to an entity, the column contains "default". |
72
69
73
70
## About the entities details page
74
71
@@ -132,17 +129,15 @@ or criticality for one or more entities.
132
129
### Update entities from the UI
133
130
134
131
1.[**New UI**](/docs/get-started/sumo-logic-ui). In the main Sumo Logic menu select **Cloud SIEM > Entities**. You can also click the **Go To...** menu at the top of the screen and select **Entities**. <br/>[**Classic UI**](/docs/get-started/sumo-logic-ui-classic). Click **Entities** at the top of the screen.
135
-
1. Note that there is a checkbox at the left end of each entity row, and one above the entities list. <br/><img src={useBaseUrl('img/cse/entities-page.png')} alt="Entities page" style={{border: '1px solid gray'}} width="800"/>
136
-
1. Click the top checkbox to select all of the entities on the page, or click the checkbox next to each entity you want to update.
137
-
1. Note that once you select an entity, three options appear at the top of the entities list. <br/><img src={useBaseUrl('img/cse/update-options.png')} alt="Update options" style={{border: '1px solid gray'}} width="800"/>
138
-
<br/>See the instructions for each option below:
139
-
*[Update tags](#update-tags)
140
-
*[Update suppression](#update-suppression)
141
-
*[Update criticality](#update-criticality)
132
+
1. Note that there is a checkbox at the left of each entity row, and one above the entities list. Click the top checkbox to select all of the entities on the page, or click the checkbox next to each entity you want to update.
133
+
1. Note that once you select checkboxes for multiple entities, a box slides out showing three options above the list of selected entities. See the instructions for each option below:
1. After selecting the entities you want to update, click **Update Tags**.
140
+
1. After selecting the entities you want to update, click **Change Tags**.
146
141
1. Click the down arrow to display the options: <br/><img src={useBaseUrl('img/cse/tag-options.png')} alt="Tag options" style={{border: '1px solid gray'}} width="400"/>
147
142
***Add.** Select this option to add one or more tags to the entity, without affecting any tags already assigned to the entity. You’re prompted to select a tag. If you select a schema tag, you’re prompted to select a tag value. You can select multiple tags to add.
148
143
***Remove**. Select his option to remove one or more tags from the entity. You’re prompted to select a tag. If you select a schema tag, you’re prompted to select a tag value. You can select multiple tags to remove. If a selected entity doesn't have the specified tags, no change will be made to the entity.
@@ -151,19 +146,17 @@ or criticality for one or more entities.
151
146
When you use the **Replace** option, be sure to specify new tags. If you do not, the existing tags will still be removed.
152
147
:::
153
148
1. As you select tags, they’ll appear in the update popup. <br/><img src={useBaseUrl('img/cse/tags-to-add.png')} alt="Add tags to entities" style={{border: '1px solid gray'}} width="400"/>
154
-
1. When you are done selecting tags, click **Update Entity Tags**.
149
+
1. When you are done selecting tags, click **Confirm**.
155
150
156
-
#### Update suppression
151
+
#### Change suppression
157
152
158
-
1. After selecting the entities you want to update, click **Update Suppression**.
159
-
1. The **Update Suppression** popup appears, with the suppression toggle set to **Not Suppressed**. <br/><img src={useBaseUrl('img/cse/before-suppression.png')} alt="Update suppression" style={{border: '1px solid gray'}} width="400"/>
160
-
1. If you want to unsuppress the selected entities, click **Update Entity Suppression**. Otherwise, if you want to suppress the entity, toggle the slider to **Suppressed**, supply a comment if desired, and then click **Update Entity Suppression**.
153
+
1. After selecting the entities you want to update, click **Change Suppression**. A popup appears, with the suppression toggle set to **Don't Suppress**. <br/><img src={useBaseUrl('img/cse/before-suppression.png')} alt="Update suppression" style={{border: '1px solid gray'}} width="400"/>
154
+
1. If you want to suppress the entities, toggle the slider to **Suppress**, supply a comment if desired, and then click **Confirm**.
161
155
162
-
#### Update criticality
156
+
#### Change criticality
163
157
164
-
1. After selecting the entities you want to update, click **Update Criticality**.
1. If you want to assign default criticality to the selected entities, click **Update Entity Criticality**. Otherwise, use the down arrow to view defined Criticalities, select one, and then click **Update Entity Criticality**.
158
+
1. After selecting the entities you want to update, click **Change Criticality**. The **Change Criticality** popup appears. <br/><img src={useBaseUrl('img/cse/update-criticalities.png')} alt="Update criticalities" style={{border: '1px solid gray'}} width="400"/>
159
+
1. If you want to assign default criticality to the selected entities, click **Confirm**. Otherwise, use the down arrow to view defined criticalities, select one, and then click **Confirm**.
0 commit comments