Customize the events view
Customize the events view to display only the columns and information that are relevant to your monitoring and analysis needs. This allows you to optimize the view for better performance and easier data interpretation.
Any changes made to the Event Logging page are automatically saved for when you navigate away from this page and come back at a later time.
Note | The Live and Historical events view have the same configuration. When you customize the events view, these changes are applied to both the Live and Historical view. |
Procedure
Step 1 | Click the column filter icon You can modify the event view for both live and historical events to only include column headers that apply to the view you want. |
Step 2 | Select or deselect the columns you want. Columns with asterisks are provided within the event table by default, although you can remove them at any time.
|
Step 3 | Click Apply. |
Step 4 | Search for additional columns not part of the default list and add them to the event view. You can search for more columns, which are not part of the default list, and add them to the event view for both live and historical events. Note that adding many columns for customizing the table may reduce performance. Consider using fewer columns for faster data retrieval. Alternatively, click the + icon next to an event to expand it and view the hidden columns. Note that some of the event fields displayed when you expand an event can have a different name compared to the corresponding column name. To correlate the events fields displayed when you expand an event to the corresponding column name, see Correlate Threat Defense Event Fields and Column Names. |
Step 5 | Reorder the columns by dragging and dropping them in the column filter menu. Click the column filter icon |
The events view is customized with your selected columns and preferred order. These settings are automatically saved and will persist when you navigate away from and return to this page.