Cisco Cisco Firepower Management Center 4000

Page of 1844
 
46-7
FireSIGHT System User Guide
 
Chapter 46      Using Custom Tables
  Modifying a Custom Table
The Custom Tables page appears.
Step 2
Click 
Create Custom Table
.
The Create Custom Table page appears.
Step 3
In the 
Name
 field, type a name for the custom table, such as 
Correlation Events with Host 
Information (Src IP)
.
Step 4
From the 
Tables
 drop-down list, select 
Correlation Events
.
The fields in the Correlation Events table appear in the 
Fields
 list.
Step 5
Under 
Fields
, select 
Time
 and click 
Add
 to add the date and time when a correlation event was generated.
Step 6
Repeat step 
Policy
 and 
Rule
 fields.
Tip
You can use Ctrl or Shift while clicking to select multiple fields. You can also click and drag to select 
multiple adjacent values. However, if you want to specify the order the fields appear in the table view of 
events associated with the table, add the fields one at a time.
Step 7
From the 
Tables
 drop-down list, select 
Hosts
.
The fields in the Hosts table appear in the 
Fields
 list. For more information on these fields, see 
.
Step 8
Add the 
IP Address
NetBIOS Name
OS Name
OS Version
, and 
Host Criticality
 fields to the custom table.
Step 9
Under 
Common Fields
, next to 
Correlation Events
, select 
Source IP
.
Your custom table is configured to display the host information you chose in step 
initiating, hosts involved in correlation events.
Tip
You could create a custom table that displays detailed host information for the destination, or 
responding, hosts involved in a correlation event by following this procedure but selecting 
Destination IP
 
instead of 
Source IP
.
Step 10
Click 
Save
.
The custom table is saved.
Modifying a Custom Table
License: 
FireSIGHT
You can add or delete fields in a custom table as your needs change.
To modify a custom table:
Access: 
Any/Admin 
Step 1
Select 
Analysis > Custom > Custom Tables
.
The Custom Tables page appears.
Step 2
Click the edit icon (
) next to the table you want to edit.