Create a Widget using the Widget Builder
Create a widget in the Widgets Library in Cortex XSOAR
and then add widget to a dashboard or report. reports dashboard
- (Optional) If editing an existing report or dashboard, clickAdd Widget.
- In theWidgets Libraryclick the+button.
- From the drop down list, select one of the data type widgets, such asIncidents.The relevant data is fetched into the data type. For example, when creating an incident type widget, the results are fetched. You can see a preview of the widget on the right hand side.
- From theQuick chart definitionswindow, in theQuery, define the widget data.
- Add the following information:ParameterDescriptionWidget typeSelect one of the widget types, by clicking on one of the graphics, such as pie chart, line chart, etc.Widget nameType a meaningful name for the widget.Data sourceThe type of data to query.
- Incidents
- Indicators
- SOAR Metrics
- War Room Entries
- Tasks
- Scripts
- Threat Intel Reports
widgetlabel.QueryQueries data in the Lucene query syntax form relating to the data source. For example when the data source is incidents and the query is:-status:closed and owner:"", it queries all incidents that are not closed, which does not have an owner.ScriptSelect the script that you added when Create a Custom Widget Using an Automation Script Add the argument values, if required.Date rangeThe time frame to retrieve data. - Select how you want to display the information, such as pie chart, timer widget, etc. You can see a preview of how the widget appears.
- Configure the data as required, by clicking theOperationstab.Not relevant for Script and Entries types.
- In theValuessection, select one of the following values:
- Count
- Average
- Sum
- Min
- Max
- (Not relevant for Count) Select one of the fields from the drop down list or create your own custom calculations by selectingCustom calculations on fields.
- If adding custom calculations, type the calculation as required.The custom calculation modal suggests incident fields based on the widget data type, which are automatically validated. You can add your own fields (provided these fields exist), according to the widget data type, by using the CLI name. These fields are not validated.
- In theGroup byfield, from the dropdown list, select the group you want to add.By default the results are limited to the top 10 most popular results. If you want to change the top most popular to the least popular, change the number, or you want to see the remaining results that are not covered in one group (theShow ‘Others’checkbox), click the edit button and update as required.If you want to add a custom field, ensure that the Make data available for search field is checked, when editing or creating a new field.
- (Optional) To define the groups (for example, you may want to define particular owners in the owner group) do the following:
- ClickCustom ‘Group by’.
- In theCreate Custom groupswindow, clickEquals (String)to change the operator.
- Select a value from the dropdown list.
- Change the name as required.
- If you want to create a second group, clickAdd custom group.
- If you want to add a group for all other values that have not been defined, click theCreate and display a group for all remaining valuescheckbox.
- In theSecond group byfield, add the group as required. For example, to see data filtered by owner and severity, selectGroup ByOwner andSecond Group bySeverity.
- Define how the widget appears by clicking theVisualstab.
- Add the following information:ParameterDescriptionAxis nameThe name of the axis for both horizontal and vertical.FormatSelect the format of the table for both horizontal and vertical axis. For example, hours, minutes, days, weeks, etc.Reference LineWhether you want a line showing the average, minimum, maximum, or custom line.Show LegendWhether you want to see the legend in your widget.Show also percentageDisplays the percentage when selecting a pie chart.Show values of the graphAdd the values on the chart widget.Display trendCompares dates for a particular period in a number widget. For example, this week vs. last week, this year vs. last year, and so on. To change the comparison period, in theTime framefield from the drop down list, select the relevant date.Widget color thresholdSelect theWidget color thresholdnumber or duration widget to highlight the threshold data and define the threshold by selecting the Widget color threshold check box. For example, if less than 150 red, 100 yellow, 50 green. To add more thresholds, clickAdd new threshold. You can change the colors as required.
- To change the color, in the preview section, hover next to the legend, click the ellipsis and then clickEdit color.
- ClickSave.The widget is added to the widgets library.
- Add the widget to the dashboard or report.When you add the widget, it automatically uses the date range of the dashboard or report. You can change it by clicking the settings icon and selecting Use widget’s date range. To revert, click the settings icon again and select Use dashboard’s date range
Recommended For You
Recommended Videos
Recommended videos not found.