Configure the Security Analyst Workspace
Configure the user interface of the Incident record in the Security Analyst Workspace to specify the fields you want to display.
Before you begin
Role required: sn_si.analyst
About this task
Specify the fields to be displayed in your Incident record and the order in which the fields must appear on the Security Incident form and the Response Task form. You can also set a limit on the number of fields that you want to display.
Note: You can create rules to determine which view should be used for a specific form. Several views are included with the base system, including the Default and SIR New UI views. Several view rules are also shipped with the base system, including the All Others Response Task rule. This rule enforces the Default view on the Response Task form when the condition specified in the view rule is met. The Security Analyst Workspace uses the SIR New UI view. If the form fields displayed in the Security Analyst Workspace don’t match the form fields in the classic environment, a view rule is most likely enforced. To use the SIR New UI view for the form, you must disable the view rule. See Control when the system displays a view for the details.
Procedure
Navigate to All > Security Incident > Incidents > Show All Incidents.
To open the security incident record, select a security incident.
To navigate to the Configuring Security Incident form page, select the
Context menu menu icon and select **Configure** > **Form Layout**.
From the View name list, select New UI - Form Layout Configurations.
In the Section field, select the appropriate section.
This can be Security Incident or Security Incident Response Task.
Select the fields and the order in which you want them to appear in the Incident banner in the new UI.
Select Save.
Note:
- Certain fields are hidden by default in the Incident and Response Task banners. Change the fields that are hidden or displayed by modifying the
sn_app_secops_ui.form.excluded_fields.incidentandsn_app_secops_ui.form.excluded_fields.response_taskproperties as described in Security Analyst Workspace properties. - Specify the number of fields that can be displayed in the Incident and Response Task banners and on the first line of the Incident banner by setting these properties:
- sn_app_secops_ui.task_summary.single_summary.limit.incident
- sn_app_secops_ui.task_summary.single_summary.limit.response_task
- sn_app_secops_ui.task_summary.single_summary.limit.incident.first_line
- To configure the styles of the dotted circles that appear next to a field value in the Incident record, for example,
- Certain fields are hidden by default in the Incident and Response Task banners. Change the fields that are hidden or displayed by modifying the
Menu style navigate to **System UI** > **Field Styles** and modify or create a style record for the specific table and field name.
The property background-color in the Style field of the style record determines the color of the dotted circle.
To view the updated incident banner, navigate to Security Incidents > Incidents (New UI) and refresh the page to view the updated Incident banner.
To configure the Response Task banner in the Incident record, navigate to Security Incidents > Response Tasks > Show All Tasks and repeat the steps.
If you’re creating a task table extending from the base Security Incident Response Task table, you must also add the SIR New UI view to the table.
From the View Name list, select New.
Enter SIR New UI (case sensitive) in the Create New View window and select OK.
Result
The security incident and response task banners are updated in the Security Analyst Workspace (Manage security threats using the Security Analyst Workspace).