Creating and refining data groups


BMC Defender Server provides multiple features for grouping data or creating groups of groups. Several defaults are provided out-of-the-box, but as part of the administrative activities and setup of the system, the operator should create or refine certain group elements to help organize the data. The following groups are particularly important:

  • Address Groups—You can create groups of devices by address through the Correlation > Config > Address Groups tab. The address groups are given names that can be used in correlation threads, and that appear in the drop-down list of the Messages > Catalogs > Devices screen. The operator can view the status of device groups through the View Groups link on the Messages > Catalog > Devices screen.
  • Thread Groups—You can create groups of threads through the Correlation > Config > Thread Groups tab. These thread groups match thread titles and help organize the thread list into sections. The thread group names appear in the drop-down list of the Correlation > Threads screen. The operator can view the status of thread groups through the View Groups link on the Correlation > Threads screen.
  • Ticket Groups—You can create groups of tickets through the Tickets > Config > Ticket Groups tab. Ticket groups represent who can be assigned tickets and help organize the data into meaningful groups that are subsequently used in ticket notifications and actions. The operator can view the status of ticket groups through the View Groups link on the Tickets > Opened and Tickets > Closed screens.

These groups greatly assist in organizing the data and should be managed and maintained by the operator and administrator of the system. You can set their Initial Group preferences through the System > User Preferences tab (so that screens reflect the data of highest interest to the logged in BMC Defender Server user).

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*

BMC Defender SIEM Correlation Server 5.9