Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

MISP event data

You can review the MISP event data so that you can see detailed information about the MISP events.

MISP event data in the list view

Access the list view from MISP > MISP Event Data.

Use the list view to get a quick overview of the MISP event data.

FieldDescription
Event IDEvent ID that is assigned by MISP when the event was first created or imported into the MISP server.
InfoShort description of the event.
AnalysisCurrent stage of the analysis for the event with the following possible options:- Initial: The analysis is just beginning - Ongoing: The analysis is in progress - Completed: The analysis is complete
Threat LevelRisk level of the event. Incidents can be categorized into three different threat categories \(low, medium, high\). This field can be left as undefined. The following are the options:- Low: General mass malware - Medium: Advanced Persistent Threats \(APT\) - High: Sophisticated APTs and 0-day attacks
MISP TagsTags that are associated with the MISP event.
MISP GalaxiesGalaxies that are associated with the MISP event.
Owner OrgOrganization that owns the event on the MISP instance. This field is visible only to administrators.
Creator OrgOrganization that created the event on the MISP instance.
DistributionDistribution of the individual attribute. An attribute can have a different distribution level than the event.
MISP Event HyperlinkLink to the MISP event that is stored on the MISP server.
MISP SourceMISP source where the event is created.

MISP event data in the form view

Use the form view to get detailed information about the MISP events.

FieldDescription
Event IDEvent ID that is assigned by MISP when the event was first created or imported into the MISP server.
UUIDID that uniquely identifies events and attributes.
Creator OrgOrganization that created the event on the MISP instance.
Owner OrgOrganization that owns the event on the MISP instance. This field is visible only to administrators.
Creator UserUser who created the event in MISP.
Last ChangeDate that the event was last modified.
MISP SourceMISP source where the event is created.
Created date \(in MISP\)Date that the event was created or first imported in the MISP server.
Threat LevelRisk level of the event. Incidents can be categorized into three different threat categories \(low, medium, high\). This field can be left as undefined. The following are the options:- Low: General mass malware - Medium: Advanced Persistent Threats \(APT\) - High: Sophisticated APTs and 0-day attacks
AnalysisCurrent stage of the analysis for the event with the following possible options:- Initial: The analysis is just beginning - Ongoing: The analysis is in progress - Completed: The analysis is complete
DistributionDistribution of the individual attribute. An attribute can have a different distribution level than the event.
PublishedStatus of whether the event has been published or not. Publishing allows the attributes of the event to be used for all eligible exports and notifies users that have subscribed to the event alerts.
MISP Event HyperlinkLink to the MISP event that is stored on the MISP server.
InfoShort description of the event.
Tags \(Local\)Tags that are available on the host organization's MISP instance to enable tagging for synchronization and export filtering. MISP events are not modified when you use local tags. Local tags are always stripped before being synchronized with other MISP instances and sharing communities.
Tags \(Global\)Tags that are available globally to be shared and synchronized with other MISP instances and sharing communities. When you add global tags to MISP instances, you can modify events.
Galaxies \(Local\)Galaxies that are available on the host organization's MISP instance for synchronization and export filtering. MISP events are not modified when you use local galaxies. These local galaxies are always stripped before being synchronized with other MISP instances and sharing communities.
Galaxies \(Global\)Galaxies that are available globally to be shared and synchronized with other MISP instances and sharing communities. When you add global galaxies, MISP you can modify events.