Skip to main content
Version: Next

Observable Groups

Organize observables into groups via the Groups tab to categorize and enrich data based on common attributes. Observable groups allow you to create additional context for your observables using Names and Descriptions.

Example Use-Cases

  • Add all assets that exist in a specific region to a group. E.g.: Add all computing resources in Germany to the DE Asset Group
  • Set groups for different PCI network zones: For example PCI customers can add groups for Cardholder Data Environment (CDE) zones, DMZ, Corporate and Wireless zones

How to Create a Group

  1. Go to Observables > Groups.
  2. Click Add Asset Group or Add Identity Group.
  3. Define:
    • Name: e.g., DE Assets.
    • Condition: e.g., country = "DE"
  4. Define a "catch-all" rule for all others
  5. Use Reorder to set priority
  1. Use Preview to check the resulting grouping. Note that only the first 1000 assets are shown.
  1. Recalculate for immediate updates.

Groups update daily or on recalculation, appearing as Aggregated by observable-group in the UI. For example, grouping assets by country (e.g., USA, Germany) helps organize data for regional analysis.

Example

Group five hosts across three countries by the country field.

  • Asset Data for Hosts:
uidhostcountry
host1host1DE
host2host2DE
host3host3CH
host4host4AT
host5host5empty
  • Output after group assignment:
observable_groupuidhostcountry
DE Assetshost1host1DE
DE Assetshost2host2DE
CH Assetshost3host3CH
AT Assetshost4host4AT
Missed Assetshost5host5empty

Next Steps