Security Analyst Workspace properties
These system properties are used to configure the Security Analyst Workspace.
- Properties that are typically not modified like sys_ids and product keys.
- Properties that are modified as required like long poll intervals and user interface configurations.
| Property Name | Description |
|---|---|
Fields that are hidden by default in the response task banner. sn_app_secops_ui.form.excluded_fields.response_task |
|
Fields that are hidden by default in the incident banner. sn_app_secops_ui.form.excluded_fields.incident |
|
Background color style is applied to the fields listed here. sn_app_secops_ui.form.color_coded_fields |
|
If true, tables extended from the sn_si_task base response task table, will also have access to email templates created for the base response task table. sn_app_secops_ui.extend.base.response_task.email_templates |
|
Sets the width of each summary field in each response task banner. sn_app_secops_ui.task_summary.single_summary.width.response_task |
|
Sets the width of each summary field in each incident banner. sn_app_secops_ui.task_summary.single_summary.width.incident |
|
Sets a limit on the number of summary fields allowed in the incident banner. sn_app_secops_ui.task_summary.single_summary.limit.incident |
|
Sets a limit on the number of summary fields allowed in the response task banner. sn_app_secops_ui.task_summary.single_summary.limit.response_task |
|
Sets a limit on the number of summary fields allowed in the first line of the incident banner. sn_app_secops_ui.task_summary.single_summary.limit.incident.first_line |
|
Comma separated list of fields that may have user photos. sn_app_secops_ui.form.user_fields |
|
Sets the width of each summary field in each incident peek view. sn_app_secops_ui.task_summary.single_summary.width.incident_peek |
|
Comma separated list of fields that display time. sn_app_secops_ui.form.time_fields |
|
Controls the frequency (in milliseconds) at which the sighting search results are refreshed. sn_app_secops_ui.poller_interval.search_action |
|
Controls the frequency (in milliseconds) at which the count or query data is refreshed. sn_app_secops_ui.poller_interval.related_list |
|
Controls the frequency (in milliseconds) at which the result data is refreshed (for the playbook). sn_app_secops_ui.poller_interval.playbook_tasks |
|
ID for the Security Operations Integration - Isolate Host workflow. sn_app_secops_ui.workflow.id.isolate_host |
|
ID for the Security Operations Integration - Watchlist workflow. sn_app_secops_ui.workflow.id.publish_to_watchlist |
|
ID for the Security Operations Integration - Block Request workflow. sn_app_secops_ui.workflow.id.block_request |
|
ID for the sn_si_analyst user role. sn_app_secops_ui.roles.id.sn_si.write |
|
ID for the sn_si_read user role. sn_app_secops_ui.roles.id.sn_si.read |
|
ID for the sn_si_admin user role. sn_app_secops_ui.roles.id.sn_si.admin |
|
ID for the Microsoft Exchange - Perform Email Search and Delete workflow. sn_app_secops_ui.email.phishing.manual.workflow |
|
ID for the Add to Deny list custom action under the Explore tab in the Security Analyst Workspace. sn_app_secops_ui.explore.action.direct.id.deny_list |
|
ID for the Add to Allow list custom action under the Explore tab in the Security Analyst Workspace sn_app_secops_ui.explore.action.direct.id.allow_list |
|
ID for the Run Threat Lookup UI Action. sn_app_secops_ui.explore.action.id.run_threat_lookup |
|
ID for the Threat Lookup integration capability. sn_app_secops_ui.explore.capability.id.threat_lookup |
|
ID for the Observable Enrichment custom action under the Explore tab in the Security Analyst Workspace. sn_app_secops_ui.explore.action.id.observable_enrichment |
|
ID for the Enrich Observable integration capability. sn_app_secops_ui.explore.capability.id.observable_enrichment |
|
ID for the Publish to Watchlist UI Action. sn_app_secops_ui.explore.action.id.publish_to_watchlist |
|
ID for the Block Request UI Action. sn_app_secops_ui.explore.action.id.block_request |
|
ID for the Run Sightings Search UI Action. sn_app_secops_ui.explore.action.id.sightings_search |
|
ID for the Create Child Security Incident UI Action. sn_app_secops_ui.explore.action.id.create_child_incident |
|
ID for the Add Security Annotation UI Action. sn_app_secops_ui.explore.action.id.add_security_annotation |
|
ID for the CI Enrichment Custom Action under the Explore tab in the Security Analyst Workspace. sn_app_secops_ui.explore.action.id.ci_enrichment |
|
ID for the Isolate Host UI Action. sn_app_secops_ui.explore.action.id.isolate_host |
|
ID for the Add Multiple Observables UI Action. sn_app_secops_ui.explore.action.id.multiple_observable |
|
Product key for ag-Grid-Enterprise. sn_app_secops_ui.ag-grid-license |
|