Customize Episode Review in ITSI
You can customize different properties of a saved Episode Review dashboard to better suit your organization's needs and accelerate triage and investigation. Use the Settings button to customize the look and feel of Episode Review, set the auto refresh period, add or remove columns and tabs, and configure other default settings.
Prerequisites
By default, read and write permissions are granted to all roles for a newly created view of Episode Review. To restrict permissions, see Modify analyst permissions within Episode Review in ITSI.
Create saved views
Use views in Episode Review to filter the episode list by specific custom views.
Go to the Section settings tab on the Saved Episode Reviews page to add a new section to organize your various saved views, or update the order of the sections displayed in the left side panel. You can also show or hide sections, and set whether to expand the section contents by default.
Configure display settings
To update the display for various settings on the Episode Review dashboard, select the Settings button to open the display configuration modal.
Change the list display
You can change the following display settings on the dashboard:
-
Table data: view the episodes or notable events on the dashboard
-
Color by severity: each row is colored based on its severity
-
List density: determines the amount of information displayed for each episode
-
Hover to expand details: hover on each row to expand the episode row for more details
-
Display count as: set the number value to display either the total number of notable events per episode, or only the number of unique alerts (events with the same event_identifier_string).
Add and remove columns and field data
Each row in Episode Review displays a default set of columns that represent field data. You can add, remove, or rearrange columns based on which fields are important to your investigation on the Fields and data tab. For example, you might add an All Tickets column to display any ticket linked to each episode.
Show or hide tabs
Manage the sequence of tabs that display on each episode on the Tab display tab. Set a default tab (first tab), and show or hide other tabs. You can also group events together that include a specific field.
Auto refresh period
Set the frequency of when episode data is refreshed on the dashboard.
Dashboard
The dashboard and timeline visualizations are now turned off by default. Update these settings on the Dashboard tab.
Set a default view
Set a specific episode dashboard as your default dashboard. Either on the left side panel or on the Saved Episode Reviews page, select the Set as Default button in the actions menu.
Turn episode view on or off
By default, Episode Review displays episodes rather than notable events. Depending on what kind of issues your organization deals with, you might want to view individual notable events rather than episodes.
To change the episode view, select the Settings button to set your preferred page layout.
Change the default tab when viewing episodes
By default, when you select an episode listed in Episode Review, the Impact tab is displayed in the episode details panel. Depending on the types of issues you're investigating, you might want to display a more relevant tab, such as the Events Timeline or Common Fields. You can modify the default tab that's selected on a per-dashboard basis. In other words, all episodes within that Episode Review saved view will have the same tab selected by default.
To change the default tab, select the Settings button and update the tab display.
After making the change, click through several episodes to make sure the default tab has changed.