A managed security service provider (MSSP) can deploy and maintain Helix Enterprise for multiple organizations. For security and privacy, each organization requires a separate Helix Enterprise environment.
Note
In this document, the MSSP is the "parent organization" and its managed organizations are "child organizations."
The Helix Enterprise federated view Alerts page has the same features as the standard Alerts page, but it centralizes alerts across these organizations into a single federated view. This allows you to quickly find and pivot to the highest severity threats to take action on them. You can also search and hunt across organizations and build custom dashboards to compare and aggregate data.
You can take single or bulk actions on alerts for child organizations directly from the federated view Alerts page, as described later in this topic.
To view and take actions from the federated view Alerts page:
Log in to a parent organization's instance as a user with the "Tap Federated Group" access permission.
From the main menu, select Investigate > Alerts.
The top part of the Alerts page contains summary information that includes statistics about the number of alerts over the last 30 days. A chart helps you determine patterns. You can toggle between the following views:
Organizations (default)—Each organization is represented by a bar in the chart. The parent organization is represented by the leftmost bar. If you hover over a bar, the name of the organization and the number of alerts with each severity is displayed. Clicking the organization name at the bottom of the bar for a child organization navigates to the Alerts page in the child organization's instance.
Days—A bar in the chart represents consolidated alerts for a given day from the parent organization and all child organizations. If you hover over a bar section, the date and the number of alerts with that severity is displayed.
The alerts table in the bottom part of the Alerts page offers the following features in addition to the standard features of the Alerts page (described in Viewing the alerts page).
Organization column—The name of the organization associated with each alert is displayed in this column. You can click the column header to filter by organization. By default, alerts for all organizations are displayed.
menu—The standard options (View, Export, and so on) are presented for individual parent organization alerts. The same options are available for individual child organization alerts, except View in instance is available instead of View Details.You can take actions on alerts for child organizations directly from the federated view Alerts page. To perform bulk actions on parent or child organization alerts, select the alerts in the left-most column, and then select the action from the button at the top right of the table.
Active Filters—You can toggle whether you want to see only the parent organization alerts (My Org Alerts) or both the parent and child organization alerts (All Org Alerts).
Note
Organization-level functionality is also available in other parts of the Helix Enterprise Web UI, as described in Federated view.