This website uses cookies. By clicking Accept, you consent to the use of cookies. Click Here to learn more about how we use cookies.
Accept
Reject

NetWitness Community

  • Home
  • Products
    • NetWitness Platform
      • Advisories
      • Documentation
        • Platform Documentation
        • Known Issues
        • Security Fixes
        • Hardware Documentation
        • Threat Content
        • Unified Data Model
        • Videos
      • Downloads
      • Integrations
      • Knowledge Base
    • NetWitness Cloud SIEM
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Detect AI
      • Advisories
      • Documentation
      • Knowledge Base
    • NetWitness Investigator
    • NetWitness Orchestrator
      • Advisories
      • Documentation
      • Knowledge Base
      • Legacy NetWitness Orchestrator
        • Advisories
        • Documentation
  • Community
    • Blog
    • Discussions
    • Events
    • Idea Exchange
  • Support
    • Case Portal
      • Create New Case
      • View My Cases
      • View My Team's Cases
    • Community Support
      • Getting Started
      • News & Announcements
      • Community Support Forum
      • Community Support Articles
    • Product Life Cycle
    • Support Information
    • General Security Advisories
  • Training
    • Blog
    • Certification Program
    • Course Catalog
    • New Product Readiness
    • On-Demand Subscriptions
    • Student Resources
    • Upcoming Events
  • Technology Partners
  • Trust Center
Sign InRegister Now
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
NetWitness Community Blog
Subscribe to the official NetWitness Community blog for information about new product features, industry insights, best practices, and more.
cancel
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for 
Search instead for 
Did you mean: 
  • NetWitness Community
  • Blog
  • Netwitness Orchestrator Dashboarding Overview

Netwitness Orchestrator Dashboarding Overview

Bren_teo
Contributor Bren_teo Contributor
Contributor
Options
  • Subscribe to RSS Feed
  • Mark as New
  • Mark as Read
  • Bookmark
  • Subscribe
  • Email to a Friend
  • Printer Friendly Page
  • Report Inappropriate Content
3 weeks ago

Introduction

Dashboarding is an important part of RSA Netwitness Orchestrator(NWO). It is important to create a dashboard as it allows an an analyst to view data in one centralized location, and when customized effectively, displays the relevant and important data that analysts need for them to make quick decisions.

 

In this guide, it shows how to create a dashboard card and recommends some potential useful cards that analysts should have on their dashboard relating to case management.

 

How to create a dashboard

On NWO, create a new dashboard by navigating to the top tab. Under the dashboards drop down, press the option new dashboard

Bren_teo_13-1650446656906.png

Enter a name for the dashboard, like Case Management.

You will be greeted with a blank dashboard. To add a new card, navigate to the top right and press the plus button.(Next to the Padlock Icon)

Dashboard Cards are used for populating the dashboards, which is explained in the next section.

 

Bren_teo_15-1650446830365.png

 

 

 

Dashboard Cards Configuration

 

1. Case count by resolution

 

Explanation of Dashboard Card

This dashboard card displays statistics of the resolution of cases . Examples of resolutions are: “In progress/Investigating”, ”Containment achieved”.. etc

 

 

Sample Dashboard output:

Bren_teo_6-1650426397237.png

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options

Sample Image of Configuration

Card type: New Query

 

Card Name: Incident Count by Resolution

 

Display type: Chart

 

Query by: Cases

 

Grouping: Resolution

Bren_teo_2-1650425673759.png

 

 

Table of selectable resolutions in cases:

Bren_teo_3-1650425818964.png

 

 

 

 

2. Open Cases by Status

 

Explanation of Dashboard Card

This dashboard card displays the statistics of the current status of NWO cases. 

 

Sample Dashboard Output:

Bren_teo_7-1650426492189.png

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options Sample Image of Configuration

Card type: New Query

 

Card Name: Open Cases by Status

 

Display type: Chart

 

Query by: Cases

 

Grouping: Status

 

Chart type: Advanced Pie Chart

Bren_teo_5-1650426092877.png

 

 

3. Closed Case within last 24 hours

 

Note: Only available on NWO v6.3.1

Explanation of Dashboard Card

This dashboard card displays the usernames of the analysts who have closed cases within the last 24 hours.

 

Sample Dashboard Output:

Bren_teo_9-1650427003779.png

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options Sample Image of Configuration

Card type: New Query

 

Card Name: Closed Case within last 24 hours

 

Display Type: Chart

 

Query by: Cases

 

Advanced query:

caseCloseTime>="TODAY()" && caseCloseTime<"TODAY()+24 HOURS"

 

Grouping: Case close user

 

Other Charts: Number Cards
Bren_teo_8-1650426878284.png

 

 

 

4. Open Cases by Severity

 

 

Explanation of Dashboard Card

The purpose of this dashboard card is to display statistics of the number of open cases in NWO based on their severity.

 

Sample Dashboard Output:

Bren_teo_2-1650444878385.png

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options Sample Image of Configuration

Card type: New Query

 

Card Name: Open Cases by Severity

 

Display type: Chart

 

Query by: Cases

 

Advanced query: status=”Open”

 

Grouping: severity

Bren_teo_3-1650444937533.png

 

 

 

5.   Mean time to resolution

 

Note: Only available in NWO v6.3.1

Explanation of Dashboard Card

The purpose of this dashboard card is to provide a mean calculation of how long analysts took to close cases.

 

Sample Dashboard Result:

Bren_teo_0-1651115552247.png

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options Sample Image of Configuration

When creating a new dashboard card, there is a metric section. MTTR option is selected.

Card type: Metric, MTTR

 

Card Name: Mean time to Resolution

 

Important Note: A case must first be closed for this option to pop up.

Bren_teo_5-1650445094284.png

 

Bren_teo_6-1650445103497.png

 

 

 

 

 

6. Open Case Assignments

 

Explanation of Dashboard Card

All Open cases : All Open Cases in NWO will be displayed. The data that will be displayed are the name of the cases, assignee, severity and created date of the cases.

My Open Cases: Cases that are only assigned to you(current user logged in) will be displayed. The data that will be displayed are the name of the cases, severity and created date of the cases.

 

Sample Dashboard Result:

All open cases:

Bren_teo_7-1650445203817.png

My Open cases:

Bren_teo_8-1650445230117.png

 

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options Sample Image of Configuration

Card type: Widget, All Open Cases

Bren_teo_9-1650445277768.png

 

Card type: Widget, All Open Cases

Bren_teo_10-1650445292236.png

 

 

 

 

7. Incidents by Category

 

Explanation of Dashboard Card

This dashboard card provides an overview of the case count against the categories that they were assigned.

 

Sample Dashboard Result:

Bren_teo_11-1650445908360.png

 

To achieve the dashboard card shown above, refer to the following: 

Configuration Options Sample Image of Configuration

Card type: New Query

 

Card Name: Incidents by Category

 

Display Type: Chart

 

Query by: Cases

 

Grouping: Tag

 

Optional Advanced query:

tag!=”Netwitness”(If you are using the playbooks included in the starter pack, it will automatically assign the tag Netwitness so it is best to omit it)

Bren_teo_12-1650445942066.png

 

 

 

 

Conclusion

NWO features easily customizable dashboards to fit an individual analyst’s needs. There are many configuration options that Netwitness Orchestrator offers in terms of dashboarding, this only shows some examples to help you get started. I hope this blog post gives you some insight and was informative, and gives you some inspiration on how to populate your own dashboards with data that interests you.

1 Like
Share

You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.

  • Comment
Latest Articles
  • Ransomware Email Attacks: Beware of BazarLoader
  • Detecting Impacket with Netwitness Endpoint
  • Exotic Lily: Global Activity Analysis
  • Threat Research Data Hygiene Exercise: Retirement of Threat Research Intelligence Content and Report...
  • Netwitness Orchestrator Dashboarding Overview
  • Highlights from Recent Releases - Here's What's New in NetWitness Platform 11.7 and 11.7.1
  • NetWitness News Bytes: Improved Broker Query Experience
  • NetWitness News Bytes: Meta Only Event Reconstruction
  • NetWitness News - Press Releases
  • Endpoint Bundle Tuning
Labels
  • Announcements 52
  • Events 2
  • Features 9
  • Integrations 6
  • Resources 56
  • Tutorials 21
  • Use Cases 20
  • Videos 116
Powered by Khoros
  • Blog
  • Events
  • Discussions
  • Idea Exchange
  • Knowledge Base
  • Case Portal
  • Community Support
  • Product Life Cycle
  • Support Information
  • About the Community
  • Terms & Conditions
  • Privacy Statement
  • Acceptable Use Policy
  • Employee Login
© 2022 RSA Security LLC or its affiliates. All rights reserved.