Skip to main content

SIEM > search results > columns

  • September 25, 2024
  • 2 replies
  • 37 views

Chris_B
Forum|alt.badge.img+8

Hi SIEM searchers!

SIEM does not yet have a means to share selected columns for a SIEM  search.

I can share a link of a SIEM search (or use Search Manager to share a search) , my team mate will see the syntax of the search, the time span, and see results of the search... but they do not see column view I defined for my view of these search results. Instead they see which ever column view they used last.

Anytime I meet with a Google person I remind thme that this is a big deal, particularly for MSSP adoption: it's vital that the same set of tools is rolled out to each analyst so each analysis is done consistently to a high level of service. Instead a lot of time is taken socializing the best column views and making sure every analyst s using the same ones.

On the other hand perhaps one of our community members has something that can ease the pain of sharing columns?

 

2 replies

dnehoda
Staff
Forum|alt.badge.img+16
  • Staff
  • September 27, 2024

Does your teammate have the same permissions as you?


Chris_B
Forum|alt.badge.img+8
  • Author
  • Silver 2
  • September 27, 2024

Thx for the reply

Yes, even with the samepermissions SIEM does not yet have sharing of Columns sets as a functionality.

(Unless it's a preview feature that's not in my instance yet)