Organizations such as managed security service providers (MSSPs) deploy and maintain multiple Helix child organizations for compliance or privacy. The Helix federated view allows users with federated access permission to log in to a parent organization's instance. From here, you can view and manage alerts and cases for both the parent organization and the child organizations. It also allows you to search parent and child organizations and view and configure appliances that belong to the parent and child organizations from the Helix Web UI.
Note
In this content, the MSSP is the parent organization and its managed organizations are child organizations.
In a federated setup, intelligence feeds (also known as observable feeds) that Helix creates based on local signatures it collects from appliances can be shared across all enabled organizations.
The federated view provides the following:
Custom Dashboards — You can select the organizations to include in a custom dashboard, and view the
orgIandorgNamekey-value pairs for each organization.Alerts page — Consolidates alerts for the parent organization and its child organizations. You can sort and filter by organization and take alert actions for both parent and child organizations from the federated view Alerts page. For details, see About the alerts page in federated view.
Cases page — Consolidates cases for the parent organization and its child organizations. You can sort and filter by organization and take case actions for both parent and child organizations from the federated view Cases page. For details, see About the cases page in federated view.
Search page — You can search one or more organizations at the same time. Select the required organizations from the Selected Customers drop-down list under the Search bar. The
_metadata_.customer_idkey associates each search result with a particular organization. You can click a row of the table to open a side panel with more information on the search result, or select the checkbox next to each result to export or add the search result to a new or existing case.Rules page — Consolidates rules for the parent organization and its child organizations. Select an organization from the Tenant ID drop-down menu to see the rules for each tenant.
Tags page — Consolidates tags for the parent organization and its child organizations. Select an organization from the Tenant drop-down menu to see the tags for each tenant.
Appliance Management — The federated version of the Appliances page lists all appliances managed by an organization. You can quickly scan information about each appliance, such as its status, name, model, whether updates are available, and so on. A menu provides options to view health details for the appliance, pivot to the Central Management System Web UI (if one is configured in Helix), and pivot to the Appliance Settings page to configure or update an appliance. For details, see Viewing appliances and Configuring appliance settings.
Observable Feeds Sharing — The Observable Feeds Sharing page includes a switch that allows organization admins to enable federated feed sharing on their organizations. Feeds generated on any eligible appliance in an enabled parent or child organization are propagated to eligible appliances in other enabled organizations. Users in the parent and child organizations can view feeds and enable or disable feeds at various levels for granular control. For details, see Creating and sharing intelligence feeds.