Contents
1. Concept
Categories provide the ability to tag NEXThink objects in order to create custom groups based on your own organization and processes. By using Categories, you can easily create investigations on specific groups, or create widgets with metrics grouped by categories.
2. Highlights
A Tag is defined as a [Category + Keyword] pair
The number of categories and the number of keywords per category is unlimited
Each object can have only one keyword per category
If no specific keyword is configured for an object, it is considered as empty
Tagging can be done manually with NEXThink Finder or automatically defined with auto-tagging rules
Auto-tagging is a persistent object property set in two specific situations - (1) as soon as a new object appears and (2) when the auto-tagging configuration is applied.
Tagging based on a CSV file is supported
3. Examples
Some simple examples of categories and keywords
Objects |
Categories |
Keywords |
Sources |
Location |
Bern |
Users |
Department |
Backoffice |
Applications |
Packages |
Master |
Binaries |
Threats |
Malware |
Destinations |
Servers |
Exchange Cluster |
3.1. Locations with mobile users
You want to create a category Location, and you have users in Paris, users in London and some mobile users working in London, in Paris and at home. A tag is unique per object. Since you are not allowed to configure multiple keywords from the same category to one object, choose the keywords to cover all the possible cases.
You can create three keywords (Paris, London and Mobile) and set for each computer the corresponding tag.
In Finder, the results will be the following:
In Portal, the results will be the following:
3.2. Users in several countries and several departments
You have users in three countries, Switzerland, France and Spain and for each country, the same departments exists which are Sales, Services and Management.
If you want to create a widget (in Portal) with grouping by countries or by department, you can create one category Country with the three keywords Switzerland, Spain and France and one category Department with the three keywords Sales, Services and Management.
In Finder, the results will be the following:
In Portal, the results will be the following:
If you want to create widgets with grouping by countries and by departments, you can create one category Country-Department with the nine keywords: CH-Sales, CH-Services, CH-Management, F-Sales, F-Services, F-Management, SP-Sales, SP-Services and SP-Management.
The result will be as follows in Finder.
The result will be as follows in Portal.
