Skip to main content

DashboardDashboards Guide

Create a Visualization

Visualizations are stored in a visualization library and can be used in multiple dashboards. You can create new visualizations either as independent entities, which can later be added to a dashboard, or as part of an existing dashboard.

Note

For examples of the different types of visualizations you can add, see Chart Types.

  1. Enter visualization edit mode – To enter the visualization creation process, do one of the following:

    • From the Dashboards home page, click the Visualizations tab at the top and then click New Visualization.

      visualization-create-from-home.png
    • From inside of an existing dashboard, click Add Visualization at the top and then select Create new.

      visualization-create-from-dashboard.png

    A dialog box opens and displays the available Exabeam data models. The models displayed depend on the Exabeam products in your environment.

  2. Select a data model – To select a data model for your visualization, select an option from one of your Exabeam products.

    Select-Data-Model.png

    A visualization dialog box opens where you can select the dimension fields you want to visualize and the measure fields you want to use to quantify the visualized dimensions.

  3. Auto-create a visualization from a natural language prompt (Optional step) – As part of Exabeam Copilot and its set of AI-driven capabilities, you can use the natural language prompt at the top of the dialog box to quickly auto-generate your visualization. For information about using the natural language prompt, see Auto-Create a Visualization from a Natural Language Prompt.

    Note

    This auto-create option is currently available only for Event model visualizations.

    If you do not want to use this feature, proceed with the following steps to configure your measures, dimensions, and filters manually.

  4. Add measures – On the left side of the dialog box, click Edit in the upper right corner of the Measures panel.

    When you expand the Measures panel, it contains two sections. The In Visualization section shows the measures you've selected for inclusion in the visualization. The Available Measures section provides categories of available measures to choose from. The measure categories are similar to the categories of fields you are used to seeing in the Basic Search service. They include: a set of Recommendation measures, Common fields, Custom fields, and metadata. When you hover over an available field, a tooltip is displayed that includes the field's Common Information Model name and a description. You can also use the Search field to help you find a specific measure.

    measure-select-by-cim.png

    In the Measures panel, you can:

    • Click the expand (icon-expand.png) and collapse (icon-collapse.png) arrows to navigate the lists of available measures, or use the Search field to find a measure field quickly.

      Tip

      If you use the Search field to locate measures, don't forget to remove the search term when you look for the next measure.

    • Click the plus icon (icon-plus.png) on an available measure to add it the the visualization. The number next to In Visualization will increment as you add measures.

    • Click the delete icon (icon-x.png) next to a selected measure to remove it from the visualization.

    • Click Edit in the upper right corner to collapse the panel. It will display the selected measures and you can still click to remove a specific measure.

      measure-select-collapse.png
  5. Add dimensions – On the left side of the dialog box, click Edit in the upper right corner of the Dimensions panel.

    When you expand the Dimensions panel, it contains two sections. The In Visualization section shows the dimensions you've selected for inclusion in the visualization. The Available Dimensions section provides categories of available dimensions to choose from. The dimension categories are similar to the categories of fields you are used to seeing in the Basic Search service. They include: a set of Recommendation dimensions, Common Fields, Custom Fields, Metadata, Anomalies, Audit Logs, Rules, and Geo IP. When you hover over an available field, a tooltip is displayed that includes the field's Common Information Model name and a description. You can also use the Search field to help you find a specific dimension.

    dimension-select-by-cim-with-rules.png

    Tip

    In some categories of dimensions, such as Rules and Geo IP, certain dimensions can be expanded to find additional dimensions. For example, under Rules, you can find Mitre labels, which can be expanded to show additional more specific dimensions such as Tactic and Technique.

    dimension-select-by-cim-expanded.png

    In the Dimensions panel, you can:

    • Click the expand (icon-expand.png) and collapse (icon-collapse.png) arrows to navigate the lists of available dimensions, or use the Search field to find a dimension field quickly.

      Tip

      If you use the Search field to locate dimensions, don't forget to remove the search term when you look for the next dimension.

    • Click the plus icon (icon-plus.png) on an available dimension to add it the the visualization. The number next to In Visualization will increment as you add measures.

      Tip

      Select only the dimensions you want to display in the visualization. If you want to filter on a dimension that you do not want to display, do not select it as a dimension. Instead set a filter, as shown in Edit Filters below.

    • Click the pivot icon (icon-pivot.png) to designate a dimension as a pivot field in the visualization. To remove the pivot from a dimension, click the pivot icon again.

    • Click the delete icon (icon-x.png) next to a selected measure to remove it from the visualization.

    • Click Edit in the upper right corner to collapse the panel. It will display the selected measures and you can still click to remove a specific measure.

      dimension-select-collapse.png

      Note

      If you selected the Event model type, in Step 2, to start your visualization, the Approx Log Time is automatically included as a filter set for 2 days. You can change the filter but not delete it. Other model types do not include this log time filter by default, but you can add it.

    • There are a some optional steps you can take when working with dimensions:

      • Create a custom measure from a dimension field – While the dimension is still in the Available Dimensions list, move your cursor over the dimension and click the options icon (icon-options.png). Select one of the available aggregation functions to be applied to the dimension: Count distinct, List of unique values, Minimum, Maximum, Sum, Average. The custom measures are added to the In Visualization section of the Measures tab.

        Note

        Minimum, Maximum, Sum, and Average are available only for numeric dimensions, such as Rule Count or Attachment Count.

      • Create a custom data group from a dimension field – While the dimension is still in the Available Dimensions list, move your cursor over a dimension and click the options icon (icon-options.png). Select the Group option. The Group By dialog box opens. Add a Custom Field Name for the new group. In the Groups section, define the conditions you want to use to group the data. For example, in the image below, the email_address dimension is being grouped by personal vs work email addresses. Any remaining activity will be grouped under other. When you've defined the groups, click Save. The custom data group is added to the In Use tab under Custom fields.

        group-by-email.png
  6. Review your measures and dimensions – When you have selected dimensions and measures, review your selections. You can do the following in the In Visualization section of each panel:

    • Reorder dimensions and measures – Click the move icon (icon-move.png) on the left side of a dimension or measure field and drag the field to a new position in the In Visualization section.

    • Designate a dimension as a pivot field – Click the pivot icon (icon-pivot.png) on the right side of a dimension field. To remove the pivot, click the pivot icon again.

    • Remove a dimension or a measure – Click the delete icon (icon-delete.png) on the right side of a dimension or measure field.

  7. Configure filters – To add filters to the visualization, click the expand icon (icon-expand.png) on the far right side of the Filters panel. For more information about creating filters or using context filters, see Configure Visualization Query Filters.

    filters-expand.png
  8. Add a visualization title – In the upper-left corner of the dialog box, click in the title field and replace the placeholder text with a descriptive title, as in the following example:

    visualization-title-field.png
  9. Run the visualization data – Click icon-run.png Run Data button on the left, below the Dimensions panel. A data table is generated in the Data tab of the main panel on the right. The data table displays the selected dimensions and their metrics. The number of rows in the data table is listed on the right just above the Data tab.

    data-table.png

    Note

    If the icon-run.png Run Data icon turns red after the data table is generated, the data has changed and the table is not up-to-date. To refresh the data, click the the icon-run.png Run Data icon again.

  10. Configure the data table – You can opt to interact with the data table in the following ways:

    • Change the number of data rows displayed – Click in the Row limits box and change the number of rows you want to display.

    • Change the sort order of the data – To control the way data appears in a visualization, you can sort the data in any column in the data table. Click the column header to toggle between ascending and descending order.

    • View and copy the data in a SQL query format – To view the data table in a SQL format, click the SQL icon (icon-sql.png) in the top right corner of the data table. A SQL dialog box opens. At the bottom of the dialog box, click Copy. You can then paste the SQL data into an application or file of your choice.

  11. Add a chart – To add a chart to the visualization, click the Chart tab at the top of the main panel. Choose a chart type that is appropriate for the data you are visualizing. Keep in mind the following when working with charts:

    • It can be helpful to click through the different chart types to preview how they appear. If the data you have selected is not compatible with a specific chart, a message is displayed to indicate the type of dimensions and metrics needed to use it.

    • For a map chart, the visualization must include a Country Code dimension.

    • For bar and column charts, you can opt to change the series positioning. Click the settings icon (icon-series-settings.png) and then select the desired series positioning: Grouped, Stacked, or Stacked Percentage.

  12. Complete the visualization – To complete the visualization, do one of the following, depending on where you started creating it:

    • Creating from the Visualizations Tab – Click Save. The visualization is created and added to the library. You can access it for viewing and editing from the Visualization tab. If you want to be able to add the new visualization to one or more dashboards at a later time, you will first need to make it public. See Make a Visualization Public.

    • Creating from within a Dashboard – Click Add. The visualization is created and added to the dashboard where you started creating it. If you would like to add it to the visualization library, click the options icon (icon-options.png) of the visualization tile on the dashboard and select Add to Library. A library icon (icon-library.png) appears on the visualization tile next to the title.