Purpose: To flag one or more events that enables tracking those events through a workflow. See the topic, "Annotations" in ESM 101.
Where: Viewer panel displaying an active channel of events
Procedure:
Select one or more events in any active channel. If not already annotated, you can start a collaboration cycle.
Right-click the events and select Annotate Events or press Ctrl+T.
In the Annotate Events dialog popup, set or change the events' Annotations fields, as described below.
Field |
Usage |
---|---|
Click this field to choose a different disposition state for the events' collaboration cycle. The default stage is [Queued] and available stages run from Initial to Closed. If you created your own stages as described in Creating or Editing Stages, these custom stages would be displayed here. Setting the event's Stage through a rule action: You can also automate the setting of the selected event's stage through the If you want to override the rule action, add this statement to the
For the instructions on how to edit the See also Set Event Field in the Rule Actions Reference topic. |
|
Assign to |
Click this field to choose an ESM user to take the next step. |
Is Reviewed |
This read-only field tells you whether this event has been reviewed. |
In Case |
This read-only field tells you whether these events are already part of an ESM case. If they are, you have more ways to track their disposition. See Viewing a Case's Events in a Channel for related information. |
Correlated |
This read-only field tells you whether these events are part of a correlated event chain. If so, you can learn more through the rules authored to control that chain of correlation. Note: You can configure the ArcSight Forwarding Connector to send correlation events along with the correlated base events from a source Manager to a destination Manager. However, the forwarded base events display the logger.base-event-annotation.enabled = true
For instructions on how to edit the |
Hidden |
This read-only field tells you whether these events are hidden from all but the assigned users of this stage. |
Closed |
This read-only field tells you whether the investigation of these events has been marked as closed. Closed events may no longer be visible to interested parties through active channels, for example. |
Add information in the Comments field as needed to clarify the collaborative process.
To have your changes also affect related events, use the Mark Similar Events fields, as described in Mark Similar Events Fields.
Click OK to update the event.