Security Analyst Workspace properties
These system properties are used to configure the Security Analyst Workspace.
There are two types of properties:
- Properties that are typically not modified like sys_ids and product keys.
- Properties that are modified as required like long poll intervals and user interface configurations.
Note: The Security Analyst Workspace properties are located at this location: Security Incident > Analyst Workspace Setup > Analyst Workspace Properties.
| Property Name | Description |
|---|---|
| Fields that are hidden by default in the response task banner. sn\_app\_secops\_ui.form.excluded\_fields.response\_task |
|
| Fields that are hidden by default in the incident banner. sn\_app\_secops\_ui.form.excluded\_fields.incident |
|
| Background color style is applied to the fields listed here. sn\_app\_secops\_ui.form.color\_coded\_fields |
|
| If true, tables extended from the sn\_si\_task base response task table, will also have access to email templates created for the base response task table. sn\_app\_secops\_ui.extend.base.response\_task.email\_templates |
|
| Sets the width of each summary field in each response task banner. sn\_app\_secops\_ui.task\_summary.single\_summary.width.response\_task |
|
| Sets the width of each summary field in each incident banner. sn\_app\_secops\_ui.task\_summary.single\_summary.width.incident |
|
| Sets a limit on the number of summary fields allowed in the incident banner. sn\_app\_secops\_ui.task\_summary.single\_summary.limit.incident |
|
| Sets a limit on the number of summary fields allowed in the response task banner. sn\_app\_secops\_ui.task\_summary.single\_summary.limit.response\_task |
|
| Sets a limit on the number of summary fields allowed in the first line of the incident banner. sn\_app\_secops\_ui.task\_summary.single\_summary.limit.incident.first\_line |
|
| Comma separated list of fields that may have user photos. sn\_app\_secops\_ui.form.user\_fields |
|
| Sets the width of each summary field in each incident peek view. sn\_app\_secops\_ui.task\_summary.single\_summary.width.incident\_peek |
|
| Comma separated list of fields that display time. sn\_app\_secops\_ui.form.time\_fields |
|
| Controls the frequency \(in milliseconds\) at which the sighting search results are refreshed. sn\_app\_secops\_ui.poller\_interval.search\_action |
Minimum: 15000 |
| Controls the frequency \(in milliseconds\) at which the count or query data is refreshed. sn\_app\_secops\_ui.poller\_interval.related\_list |
Minimum: 15000 |
| Controls the frequency \(in milliseconds\) at which the result data is refreshed \(for the playbook\). sn\_app\_secops\_ui.poller\_interval.playbook\_tasks |
Minimum: 15000 |
| ID for the Security Operations Integration - Isolate Host workflow. sn\_app\_secops\_ui.workflow.id.isolate\_host |
|
| ID for the Security Operations Integration -Watchlist workflow. sn\_app\_secops\_ui.workflow.id.publish\_to\_watchlist |
|
| ID for the Security Operations Integration - Block Request workflow. sn\_app\_secops\_ui.workflow.id.block\_request |
|
| ID for the sn\_si\_analyst user role. sn\_app\_secops\_ui.roles.id.sn\_si.write |
|
| ID for the sn\_si\_read user role. sn\_app\_secops\_ui.roles.id.sn\_si.read |
|
| ID for the sn\_si\_admin user role. sn\_app\_secops\_ui.roles.id.sn\_si.admin |
|
| ID for the Microsoft Exchange - Perform Email Search and Delete workflow. sn\_app\_secops\_ui.email.phishing.manual.workflow |
|
| ID for the Add to Deny list custom action under the Explore tab in the Security Analyst Workspace. sn\_app\_secops\_ui.explore.action.direct.id.deny\_list |
|
| ID for the Add to Allow list custom action under the Explore tab in the Security Analyst Workspace sn\_app\_secops\_ui.explore.action.direct.id.allow\_list |
|
| ID for the Run Threat Lookup UI Action. sn\_app\_secops\_ui.explore.action.id.run\_threat\_lookup |
|
| ID for the Threat Lookup integration capability. sn\_app\_secops\_ui.explore.capability.id.threat\_lookup |
|
| ID for the Observable Enrichment custom action under the Explore tab in the Security Analyst Workspace. sn\_app\_secops\_ui.explore.action.id.observable\_enrichment |
|
| ID for the Enrich Observable integration capability. sn\_app\_secops\_ui.explore.capability.id.observable\_enrichment |
|
| ID for the Publish to Watchlist UI Action. sn\_app\_secops\_ui.explore.action.id.publish\_to\_watchlist |
|
| ID for the Block Request UI Action. sn\_app\_secops\_ui.explore.action.id.block\_request |
|
| ID for the Run Sightings Search UI Action. sn\_app\_secops\_ui.explore.action.id.sightings\_search |
|
| ID for the Create Child Security Incident UI Action. sn\_app\_secops\_ui.explore.action.id.create\_child\_incident |
|
| ID for the Add Security Annotation UI Action. sn\_app\_secops\_ui.explore.action.id.add\_security\_annotation |
|
| ID for the CI Enrichment Custom Action under the Explore tab in the Security Analyst Workspace. sn\_app\_secops\_ui.explore.action.id.ci\_enrichment |
|
| ID for the Isolate Host UI Action. sn\_app\_secops\_ui.explore.action.id.isolate\_host |
|
| ID for the Add Multiple Observables UI Action. sn\_app\_secops\_ui.explore.action.id.multiple\_observable |
|
| Product key for ag-Grid-Enterprise. sn\_app\_secops\_ui.ag-grid-license |
|