cancel
Showing results for 
Search instead for 
Did you mean: 
r_gine
Level 9
Report Inappropriate Content
Message 1 of 3

How to use 'Alarms' Dashboard

We're trying to figure out the best way to use the Alarms dashboard. We're unable to figure out how to use the 'Alarms' in a way that allows us apply basic SOC workflow functions. 

  1.  Alarm triggers
  2. Analysts acknowledges alarm
  3. Analyst begins triage
  4. Analyst decides to dismiss alarm (FP, etc) or decides to escalate (create case)

We know we can create a case easily from here, but what we cannot figure out is how/where the analyst is supposed to manage and disposition the alarm. I don't see any place to disposition or dismiss the alarm. Or to add any type of notes to the alarm. I also dont see a way to associate or collapse multiple alarms into one. 

I don't think it's realistic to move all alarms into a case management system. Is there something that I'm missing here?

 

Labels (3)
2 Replies
Highlighted
Reliable Contributor David1111
Reliable Contributor
Report Inappropriate Content
Message 2 of 3

Re: How to use 'Alarms' Dashboard

no, your not missing nothing.

theirs' no option of leaving notes etc. on the Alarms...

i posted a idea for that in the McAfee Ideas Site, but they just closed it...

sadly, no option.

 

Best Regards👍👍👍

David.

Reliable Contributor brenta
Reliable Contributor
Report Inappropriate Content
Message 3 of 3

Re: How to use 'Alarms' Dashboard

The case management inside the SIEM is pretty terrible, it was clearly added as an after though. 

Most alarms that I make are basically just "auto-acknowledged" and tied to some event, such as emailing, adding things to watchlists, etc...

You might want to try to do an integration to a ticketing system to really track things a little better.

Brent
More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator