Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

The Viewing Open Insights - Threats View page covers the Dashboard, Insight Settings, Threats View/Configuration View, and the Details Panel. The Insights dashboard provides information on threats and configurations observed on a network, displaying open insights, expiring insights during the week, medium to critical priority insights, active insights with a donut chart based on threat types and more. It assists in monitoring and managing detected threats while allowing for sorting and searching of insights. Additionally, it enables cybersecurity professionals to monitor, analyze, and respond to threats in real-time. The page also includes details about Insight Settings which allow actions to be assigned to different types of Insights for managing security policies when specific insight types are detected.

The Threats view is displayed by default but can be toggled with Configuration view depending on license availability. It displays priority levels of an insight along with recommended actions if available as well as last observation date and time among other details associated with selected Insight.
Image RemovedImage Added

Image: A detailed view of the Open insights -Threats View dashboard, which provides a comprehensive view of network security threats and insights. The interface is divided into several sections with various functionalities. The dashboard provides sophisticated tools that enable cybersecurity professionals to monitor, analyze, and respond to threats in real-time. It is designed to provide a quick overview while also allowing for in-depth analysis and immediate action to protect against security threats.

The Dashboard

call-out AImage Removedcall-out AImage Added

Open/Closed: Click OPEN to view open insights. Click CLOSED top view closed Insights. 


call-out BImage Removedcall-out BImage Added

Threats/Configuration View: The default page displays threat view information about insights observed on your network. The Threats view is displayed by default on the Insights dashboard page. Click Configuration to view configuration information for insights. Click on either Threats or Configuration to toggle between the two views. NoteThe Threats and Configuration pages are available on a license basis. 

call-out CImage Removedcall-out CImage Added

Dashboard Reporting: The dashboard displays four cards, each displaying information about the open insights reported on your network. Each card displays the number of detections for the last seven days with percentage increase or percentage decrease in total detections during the past seven days. The four small cards display the following information:

  • Total Open Insights: The total number of all open insights currently reported on your network.
  • Expiring this week: The number of open insights on your network is scheduled to expire during the coming week. 
  • Medium Priority Insights: The number of threat insights on your network determined to be a medium priority threats. 
  • High Priority InsightsThe number of threat insights on your network determined to be high priority threats. 
  • Critical Priority insightsThe number of threat insights on your network determined to be critical priority threats. 

call-out DImage Removedcall-out DImage Added

Active Insights Highlights: This information card displays a donut chart of visual data about the specific types and quantities of threats detected on your network. An upward pointing arrow reports an increase in activity for the past week while a downward pointing arrow indicates a decrease in activity over the same one week reporting period. From the card's side panel menu, you can choose to view the donut chart based on any of the following criteria:

  • Threat Types: The threat types observed on your network during the current reporting period. 
  • Threat Levels: The threat levels observed on your network during the current reporting period. 
  • Timeline: The number of events and devices observed during the past 24 hour and one week time spans. 
  • Scanned Major Threats: The results of the scan of your network for major threats 
  • Most Infected Devices: This report displays the following information acquired from any discoverable sources (Infoblox Endpoint, IP address, Metadata,etc.). 
    • UserThe username that is used to log into this device.
    • OS VersionThe OS version that is currently running on the device.
    • Mac AddressThe MAC address for the device.
    • Threat Families: The threat family class or classes observed on devices in the network. 

call-out EImage Removedcall-out EImage Added

Sort byClick Sort by to see the list of Insights sorted by date, priority, or type. 

The Sort by menu displaying options.Image RemovedThe Sort by menu displaying options.Image Added
Image: The Sort by menu options include date, priority, or type. 

call-out FImage Removedcall-out FImage Added

SearchEnter a search criterion in the Search text box. The Infoblox Portal will show all records that match the criterion.

call-out GImage Removedcall-out GImage Added

Insight Settings: Click Insight Settings to open the Insight Settings pane. In the Insight Settings pane, actions can be assigned to Insight types. If the action for the same Insight type is changed multiple times within one hour, then after one hour, only the latest action updated in the database will be applied to all the events that occurred during the past hour. See the Insight Settings section for further information.

call-out HImage Removedcall-out HImage Added

Filtering: Click the filter icon  to open and close the filtering panel.  See call-out K for additonal information on selecting filter attributes to be used for running insight record queries. 

call-out IImage Removedcall-out IImage Added

Selecting insights: Place a check in the checkbox  next to an insight to select it. You can select multiple insights by placing checks on the checkboxes associated with the desired insights. 

call-out JImage Removedcall-out JImage Added

Click Select all to select all insights. Alternatively, you can deselect all selected insights by clicking Deselect All. 

call-out KImage Removedcall-out KImage Added

Filter Query Options: Clickthe add icon to display the filter option drop-down menu.

Image RemovedImage Added
Image: The basic filtering query options include type, priority, feed source, or category. 

...

Multiple filter types can be selected simultaneously. 
Image RemovedImage Added
Image: A detail view of the filtering pane. 
call-out LImage Removed

call-out LImage Added

Insight Status: Click Insight Status > Move to Closed after selecting one or more open insights to change insight status to Closed.  You can confirm the status change of selected insights by verifying hey have been moved to the Closed Insight page. 
call-out MImage Removed

call-out MImage Added
Expand All/Collapse All: Click Expand All to expand the details pane for all Insights. Conversely, click Collapse All to collapse the details pane. Alternatively, you can use the expand/close arrows (See call-out Q) to expand and close the details pane for an Insight. 
call-out NImage Removed

call-out NImage Added

Details Pane (default and expanded view): The Details pane displays information about insights on your network: See the Details Pane section for further information. 

call-out OImage Removedcall-out OImage Added

Investigate Insight: Click Investigate Insight to view Insight Summary, Assets, Indicators, Event, Comments, and Threat Categories pages. Each page displays important information about insights detected on your network. 

call-out PImage Removedcall-out PImage Added

Editing/Closing Insights: Click the three horizontal dots icon to move the selected insight to closed or to edit the selected insight. 

...

  1. To edit an Insight, do the following:
  2. Click the three horizontal dots icon followed by clicking Edit Insight to begin the insight editing process. 
    Image RemovedImage Added
    Image: The Investigate Insight drop-down menu options include Move to Closed and Edit Insight

  3. In the edit pane, toggle the insight Open switch to the left to close the insight. In the comments field, provide information as a closing comment for the insight.
    A detail view of the Edit window.Image RemovedA detail view of the Edit window.Image Added
    Image: A detail view of the Edit window. 

  4. Click Save & Close.

...

  1. To close an Insight, do the following:
  2. Click the three horizontal dots icon followed by clicking Move to Closed Insight. The selected insight will be moved to the Closed insight list.

Image RemovedImage Added
Image: The Investigate Insight drop-down menu options include Move to Closed and Edit Insight

call-out QImage Removedcall-out QImage Added

Expand/CloseClick the down-pointing arrow icon to expand the details panel where you can view detailed information associated with the selected Insight. Click the up-pointing arrow icon to close the details panel.

...

  • INSIGHT TYPE: The type of Insight. Options include
    • DGA Types
    • DNS Tunneling
    • Lookalike Threat
    • Major Attack
    • NXDomain
    • Open Resolver
    • Outlier
    • Rapid Domain Triage
    • Spear Phishing
  • ACTIONS: Actions can be assigned to Insight types. Action options which can be applied include Nothing, Add to Allow List, and Add to Block ListIf the action for the same Insight type is changed multiple times within one hour, then after one hour, only the latest action updated in the database will be applied to all the events that occurred during the past hour.

Image RemovedImage Added
Image: The Insight Settings window. 


Actions can be applied to an Insight by selecting an option from the drop-down list. 

Image RemovedImage Added
Image: The Actions drop-down options include Nothing, Add to Block List, and Add to Allow List

...

  1. Click the three horizontal dots icon followed by clicking Edit Insight to begin the insight editing process. 

    Image RemovedImage Added
    Image: The Edit Insight drop-down menu options include Move to Closed and Edit Insight


  2. in the edit pane, toggle the insight Open switch to the left to close the insight. In the comments field, provide information as a closing comment for the insight.  
  3. Click Save & Close

...

The Threats view is displayed by default on the Insights dashboard page. The Threats and Configuration pages are available on a license basis. 

The Insight Threats view displays the following information associated with a selected Insight:

  • Priority: The priority level of the insight. 
  • Infoblox's Action/Notification: Provides information about the Insight along with recommended actions. If the action for the same Insight type is changed multiple times within one hour, then after one hour, only the latest action updated in the database will be applied to all the events that occurred during the past hour.
  • Last Observation: The time and date the insight was last detected on the network.
  • Description: A detailed description of the Insight.
  • Investigate Insight: Investigate multiple contributing factors for the reported Insight. 

The Insight Configuration view displays the following information associated with a selected Insight:

  • Priority: The priority level of the insight. Priorty level 
  • Last Observation: The time and date the insight was last detected on the network.
  • Investigate InsightInvestigate multiple contributing factors for the reported Insight. 
  • View IDS: Allows you to view or investigate Insight settings.
  • Close Service or Policy: Allows you to close a service or policy associated with the Insight.
  • Insight RecommendationsInsight recommendations are based on best practices for security policies configuration and optimization.
  • Security Policy: Displays security policy optimization issues and errors.
  • View DFP Services: Displays DNS Failover Configuration check failed issues and errors.

 Image RemovedImage Added

Image: The Open Insights dashboard page - Configuration view (normal view). The dashboard displays information about open insight records. 

The Configuration view displays the following information for a selected Insight:

call-out AImage Removedcall-out AImage Added

Priority: The insight priority level. Priority levels reported include Critical, High, Medium. Low, or Info.

call-out BImage Removedcall-out BImage Added

Status Action/Notification: The status/notification of the Insight along with recommended actions. If the action for the same Insight type is changed multiple times within one hour, then after one hour, only the latest action updated in the database will be applied to all the events that occurred during the past hour. For information on the detailed notification report, see call-out H, below. Do note that the status action/notification is not available for all insight reports and is not available for insight configurations. 

call-out CImage Removedcall-out CImage Added

Last Observation: The time and date the insight was last detected on the network. Additionally, information on the number of days the insight has been active on the network is provided. 

call-out DImage Removedcall-out DImage Added

View IDS: Click View or Investigate to Insight settings. 

call-out EImage Removedcall-out EImage Added

Click the three horizontal dots icon to close a service or policy the Insight is associated with. Or for the purposes of investigation, copy the link to share with others in your organization.

call-out FImage Removedcall-out FImage Added

Click the down-pointing arrow icon to open the details panel Click the up-pointing arrow icon to close the details panel. 

call-out GImage Removedcall-out GImage Added

Insight RecommendationsInsight recommendations are provided by the Infoblox Cybersecurity anf threat investigation teams based on best practices for security policies configuration and security policy precedence and identified issues with security policy optimization. 

  • Security Policy: For security policy optimization issues, you will be taken to the Security Policies page in the Infoblox Portal (Configure > SecurityPolicies). Security policy errors will be displayed in the Security Policy Needs Optimization pane. The Security Policy Needs Optimization pane displays the following information:
    • POLICY NAME: The name of the policy needing optimization. Note: Click on a policy name to navigate to the security policy needing attention in the Infoblox Portal. 
    • POSSIBLE ERROR: A brief description of the potential error.
    • INSIGHT ID: The Insight's identification. 

Image RemovedImage Added
Image: The Security Policy window.  

  • View DFP Services: For DFP service optimization issues, you will be taken to the DNS Failover Configuration check failed pane in the Infoblox Portal (ConfigureInfrastructure > Services). DFP service errors will be displayed in the DNS Failover Configuration check failed pane. The DNS Failover Configuration check failed pane displays the following information:
    • SERVICE NAMEThe name of the service needing optimization. Note: Click on a service name to navigate to the service needing attention in the Infoblox Portal
    • POSSIBLE ERROR: A brief description of the potential error.
    • INSIGHT ID: The Insight's identification. 

 The DFP Services window.Image Removed The DFP Services window.Image Added
Image: The DFP Services window.

  • Investigate Insight: To investigate the selected insight, you will be taken to the Insight Summary page. 

call-out HImage Removedcall-out HImage Added

Status Action/Notification (detailed report): The detailed action notification identifies potential weaknesses and issues with your insight configuration and advises on how to remedy identifies problems. 

...

The Open Insights Details pane displays information associated with the selected Insight. The information includes priority level, insight type, last observation date and time, active days, definition, creation date, feed source, categorizations, and an interactive event chart.
The Open Insights - Threats View Details Details pane (default view). The Details pane displays information about the selected insight.Image Removed
The Open Insights - Threats View Details Details pane (default view). The Details pane displays information about the selected insight.Image Added

Image: The Open Insights - Threats View Details Details pane (default view). The Details pane displays information about the selected insight.

The default view for the Details Pane displays the following information for the selected Insight. 

call-out AImage Removedcall-out AImage Added

Priority: The priority level of the insight. Priority levels reported include Critical, High, Medium. Low, or Info.

call-out BImage Removedcall-out BImage Added

Type: The insight type.

call-out CImage Removedcall-out CImage Added

Last Observation: The time and date the insight was last detected on the network. Additionally, information on the number of days the insight has been active on the network is provided. 

call-out DImage Removedcall-out DImage Added

Investigate Insight: Click Investigate Insight to be taken to the Summary page where an investigation of the insight begins. For information, see Viewing the Insight Summary

call-out EImage Removedcall-out EImage Added

Click the three horixontal dots iconfollowed by clicking Move to Close to close a selected insight or click Edit to edit the selected insight. For information on editing an Insight, see the Edit Insight section.

Image RemovedImage Added
Image
: The Investigate Insight drop-down menu options include Move to Closed and Edit Insight
call-out FImage Removed

call-out FImage Added

Click the down-facing arrow icon to expand the details pane.
Image Removed
Image Added

Image: The Open Insights - Threats View Details Details pane (expanded viewThe Details pane displays information about the selected insight.

The expanded view for the Details pane displays the following information for the selected Insight. 

call-out AImage Removedcall-out AImage Added

Priority: The priority level of the insight.

call-out BImage Removedcall-out BImage Added

Type: The insight type

call-out CImage Removedcall-out CImage Added

Last Observation: The time and date the insight was last detected on the network. Additionally, information on the number of days the insight has been active on the network is provided. 

call-out DImage Removedcall-out DImage Added

Investigate Insight: Click Investifate Insight  to be taken to the Summary page where an investigation of the insight begins. For information, see Viewing the Insight Summary.  

call-out EImage Removedcall-out EImage Added

Click the three horizontal dots icon followed by clicking Move to Close to close a selected insight, or click Edit to edit the selected insight. For information on editing an Insight, see the Edit Insight section.
The Edit Insight drop-down menu options include Move to Closed and Edit Insight.Image Removed
The Edit Insight drop-down menu options include Move to Closed and Edit Insight.Image Added
Image: The Edit Insight drop-down menu options include Move to Closed and Edit Insight
call-out FImage Removed

call-out FImage Added

Click the up-facing arrow icon to return to the details pane default view. 

call-out GImage Removedcall-out GImage Added

Selecting insights: Place a check in the checkbox next to an open insight to select it. Once selected, click Insight Status followed by clicking Move to Close to update and change the insight status.  to closed. you can close the insight.
Image RemovedImage Added
Image: The Insight Staus drop-down menu option includes Move to Closed
call-out HImage Removed

call-out HImage Added

Event chart: An event chart visually the frequency and quantity of identified events occurring during the past 31 days in a columnar chart.

call-out IImage Removedcall-out IImage Added

Description: A brief definition of the documented Insight. 

call-out JImage Removedcall-out JImage Added

Creation Date: The insight's original time and date of creation.

call-out KImage Removedcall-out KImage Added

Feed Source: The unique threat indicator(s) associated with the threat, such as domain(s) or IP address(s). 

Note
titleNote

Recommended Threat Feed Missing notification
Infoblox recommends specific threat feeds to maintain optimal security. Receiving this notification means that one or more feeds is missing from an active policy. Hover over “Threat Feeds” for additional information.


call-out LImage Removedcall-out LImage Added

CategorizationsA list of all the threat categories associated with the DNS queries on the network.  

...

  • Background TasksClick the hourglass to open the side panel to view a list of all running background tasks. 

  • Search: Click the search icon in the Search text box, then enter your search criterion. 

  • Pagination Controls: At the bottom left, there are controls for navigating through different pages of insights, indicating that there is more data available beyond what is displayed on the current page. Click on the number of insight records to display on the page. The options include, 25, 50, or 100.