Triage
Triage is working through your events: marking what you have looked at, writing down what you decided, and hiding what you do not need to see again. This page covers labels, notes and every action in the row menu.
The row menu
Every event has a menu of actions. Right-click the row to open it, or press the ⋮ button at the end of the event's label. It works the same on the events list and on the events listed inside the Map. Press Escape or click elsewhere to close it.
The menu starts with Mark (your labels, New label..., Manage labels...) and Comment.... On es-python rows it then has a Rule group, which turns the event into a rule in any of the four rule modes. On es-chromium rows it has Filter (the event's impact tags) and Block (hide events like this one) instead. Items that cannot act on the event you clicked are left out, so the menu can be shorter on some rows.
Labels
Labels are your own coloured tags for events, such as "triaged", "false positive" or "ticket filed". They are shared across all your lists, so one set of labels covers every product.
To put a label on an event, open its row menu and click the label under Mark; a tick shows it is on. Click it again to take it off. An event can carry several labels, and they appear as coloured chips on the row. To see only events with a label, pick it in the Label filter on the toolbar (see Filtering).
New label
New label... in the row menu creates a label and puts it on that event in one step. Give it a name (up to 48 characters) and pick a colour: Amber, Cyan, Red, Green, Blue, Slate, Violet or Pink. Label names must be unique.
Manage labels
Manage labels... in the row menu lists your labels. Change a name or colour and it is saved as soon as you leave the field; the chips on every event update with it. Delete removes a label after you confirm, and takes it off every event that carried it. That cannot be undone.
Notes
A note is a short comment you keep on an event, for the next person to look at it (or for you, next month): why it was checked, what was decided, the ticket number. Each event has one note, and events with a note show a ✎ marker on the row.
Choose Comment... in the row menu to write or edit it (up to 4,096 characters). The box opens with the current note, so you are editing it rather than replacing it. Save an empty note to delete it.
Rule (es-python)
On es-python rows, the Rule group turns the event you are looking at into a rule for events like it, in one of the four rule modes: Show (UI), Hide (UI), Don't send (drop) or Raise (machine). The rule matches this event's sink and its taint source, and is added to Sources & rules on the es-python Filters page, where you can edit or remove it.
- Raise (machine) appears only when Raise rules are enabled for your account (see Report and Raise).
- Don't send (drop) asks you to confirm first, because a dropped event is never stored.
- Choosing a mode that already has an identical rule adds nothing.
es-python rows do not have the Filter and Block groups described below; use the Tag filter on the toolbar to filter by impact tag.
Filter by tag
The Filter group lists the event's impact tags, for example Filter: sqli. Clicking one sets the Tag filter on the toolbar to that class, so the list shows only events of the same kind. The group is absent on events with no tags.
Block
On es-chromium, the Block items turn the event you are looking at into a standing filter that hides events like it, without retyping its details. The filter applies to the es-chromium list, takes effect immediately, and appears on the es-chromium Filters page, where you can review, switch off or delete it.
Blocking hides events from your lists; it does not stop the machine reporting them. To stop an event being reported at all, set a rule with the Drop mode.
Block this sink
Block this sink hides every event with exactly this sink label, from any source. Use it for an operation you have reviewed and do not want to see again.
Block this source
Block this source hides every event whose data came from this source, whatever sink it reached.
Block this tag
Block this tag, for example Block this tag: sqli, hides every event of that vulnerability class. It appears once for each of the event's impact tags.
A triage routine
One way to work through a busy list:
- Filter to Critical and High with the Severity filter.
- Open each event and read What this means.
- Label it (for example "fixed", "accepted" or "false positive") and add a note saying why.
- For findings that are expected and harmless, hide them: Rule > Hide (UI) on es-python, Block on es-chromium.
- Filter by label later to check what is still open, and save the view as a saved search.