Helix Enterprise federated view

Prev Next

Organizations such as managed security service providers (MSSPs) deploy and maintain multiple Helix Enterprise organizations for compliance or privacy. The Helix Enterprise federated view allows users with the "TAP Federated Group" access permission who are logged in to a parent organization's instance to view and manage alerts and cases for both the parent organization and the child organizations. It also allows users to view a list of appliances that belong to the parent and child organizations, and configure and update those appliances from the Helix Enterprise Web UI.

In a federated setup, intelligence feeds (also known as observable feeds) that Helix Enterprise creates based on local signatures it collects from appliances can be shared across all enabled organizations.

Note

In this document, the MSSP is the "parent organization" and its managed organizations are "child organizations."

The federated view provides the following:

  • Alerts page—Consolidates alerts for the parent organization and its child organizations. You can sort and filter by organization and take alert actions for both parent and child organizations from the federated view Alerts page. For details, see Using the Alert List in Federated View.

  • Cases page—Consolidates cases for the parent organization and its child organizations. You can sort and filter by organization and take case actions for both parent and child organizations from the federated view Cases page. For details, see Understanding the Cases List in Federated View.

  • Custom Dashboards—You can select the organizations to include in a custom dashboard, and view the orgI and orgName key-value pairs for each organization.

  • Searches—You can search one or more organizations at the same time. Select the required organizations from the Selected Customers drop-down list under the Search bar. The _metadata_.customer_id key associates each search result with a particular organization. You can click a row of the table to open a side panel with more information on the search result, or select the checkbox next to each result to export or add the search result to a new or existing case.

  • Search Results—The metadata_.customer_id key in Index Search Results and Archive Search Results associates each item with a particular organization. List items have a metadata_.customer_id header that provides standard pivot actions (New Search, Add to Current Search, and so on). Table items have metadata_.customer_id as the first column.

  • Appliance Management—The federated version of the Appliances page lists all appliances managed by an organization. You can quickly scan information about each appliance, such as its status, name, model, whether updates are available, and so on. A menu provides options to view health details for the appliance, pivot to the Central Management Web UI (if one is configured in Helix Enterprise), and pivot to the Appliance Settings page to configure or update an appliance. For details, see Viewing Appliance Status and Configuring Appliance Settings.

  • Observable Feeds Sharing—The Observable Feeds Sharing page includes a switch that allows organization admins to enable federated feed sharing on their organizations. Feeds generated on any eligible appliance in an enabled parent or child organization are propagated to eligible appliances in other enabled organizations. Users in the parent and child organizations can view feeds and enable or disable feeds at various levels for granular control. For details, see Creating and Sharing Intelligence Feeds.