Field Sets

The field sets panel provides access to resources that are used to group and extend the fields of the event and resource schema.

Field sets are named subsets of available data fields. Field sets can help you focus a grid view, Event Inspector, or other field array on a particular context, such as customer accounts or vulnerability.

Field sets are a shareable resource that you can manage and apply through the Field Sets resource tree in the Field Sets section of the Navigator panel. Field sets also support local and global variable data fields.

In addition to field sets based on the Security Event schema, you can create field sets based on certain resources. ArcSight supports the following types of field sets:

A base or root field set is provided for each schema type (Event, Actor, Asset, and so on) from which you can create user-defined subsets. A derived field set may inherit all or a subset of its parent's base fields, and additionally may include local or global variables not present in the parent. All field sets will have a parent (field sets created in previous versions of ArcSight will by default use the Event base field set as its parent).

Note: The ArcSightCommand Center includes a search feature, fieldset, that is different from the field set resource on the ArcSight Console.

The Field Sets tree presents tools for the following tasks:

Creating Field Sets

Creating Global Variables