Creating or Editing Stages
For a description, see the topic "Stages" in ESM 101.
Caution: Keep stages provided as standard content in the given folders and do not move them into another folder. Standard content stages are Closed, Final, Flagged as Similar, Follow-up, Initial, Monitoring, Queued, and Rule Created.
Where: Navigator > Resources > Stages
-
If you are creating a stage, right-click the All Stages group and select New Stage.
If you are editing a stage, right-click a stage under the All Stages group and select Edit Stage.
-
In the Stage Editor, enter a name for the stage.
-
Set the fields as described in the following table:
Stage Editor Fields Field
Usage
Subsequent stages
Select one or more stages to set as follow-on stages to this one. Events in this stage will show these other stages as options in the Stage field of the Annotate Fields dialog box.
User required
Select whether you want to prompt for a user assignment when assigning this stage. If you don't prompt for a different user, or no change is made, the current user remains in effect.
Comment required
Select whether you want to require users to add a comment when assigning this stage.
Can be skipped
Select whether this stage can be bypassed when assigning from one stage to the next.
Mark similar required
Choose whether you want events that are similar to the selected events to be automatically assigned to this stage. Similarity is scoped at assignment time through the Mark Similar Events fields of the Annotate Events dialog box you see when you choose Annotate in an active channel. Note that similarity marking applies only to subsequent events received in the future. Events already processed are not affected.
Mark similar stage
Select whether you want to use this stage as a routing mechanism for other stages in a workflow. When selected, assigning one or more events to this stage causes all following (subsequent) similar events to be automatically redirected to the chosen stage. Events already processed are not affected. Similarity is scoped at assignment time through the Mark Similar Events fields of the Annotate Events dialog box you see when you choose Annotate in an active channel.
Note: With the assistance of ArcSight Professional Services, you can customize the similarity criteria selector for Mark Similar events. In this way you can have conditions that are different from the defaults. This is done with the Velocity scripting language, by modifying certain Velocity templates present on the , in the
config/similaritydirectory. Ask your ArcSight administrator for more information or make a request of ArcSight Professional Services.Hidden
Select whether you want events assigned to this stage to be hidden from all but the assigned users (True), left visible to everyone (False), or to leave the current visibility unchanged (Ignore).
Closed
Select whether you want events assigned to this stage to be marked as closed to investigation (True), not marked as closed (False), or left in their previous state (Ignore).
-
Optional: To add information in the Notes tab, refer to Using Notes.
-
Click Apply to save your changes and keep the editor open, or click OK to save and close.