Skip to main content

Context ManagementContext Management Administration Guide

Context in Dashboards

In Dashboards, context data is available for use both via a pre-built IOC Statistics dashboard and by filtering on context table data in custom dashboards. For more information about each method, see the appropriate sections below.

IOC Statistics Dashboard

The IOC Statistics dashboard reflects information about the context data being collected in the built-in threat intelligence tables. This dashboard includes information about the numbers and types of IOCs found over time, as well as IOC trend analysis. For more information about this dashboard, see Indicator of Compromise (IOC) Statistics in the Dashboards Guide.

Filtering on Context Table Data When Creating a Custom Dashboard

When defining a custom dashboard visualization, context data is available by specifying a custom context table using the Context Filter option. You can filter on a custom context table of type Other or User. You can also filter on a filtered context table.

The Context Filter option is available at the bottom of the Query Filters section.

dashboard-context-filter.png

When you select the Context Filter option, you have the opportunity to select a Context Field, an Operator, and a Context Table to filter on. For example, in the image below, the condition is filtering on User values that are included in the PM IPs context table. For more information about building dashboards, see Add a Visualization in the Dashboards Guide.

dashboard-context-filter-conditions.png

Note

Certain restrictions apply to dashboard filtering when a context table lookup is included:

  • The context table can be included with an AND but not with an OR operator.

  • Only one context table can be included per dashboard visualization.

  • Only custom context tables are available for inclusion in a dashboard.

  • Active Directory context tables cannot be included directly. However, you can include a filtered context table that is created with an Active Directory context table as its source.