Skip to content
English

Signal Sets

Signal Sets are collections of signals that can be added to a case. They group signals that are important in specific processes or investigation types.

Signal sets must be customized in the library in order to be used in a case.


Open Signal Sets in the sidebar to create and manage sets. Select a row to open its properties and signals in the right panel. Library administrators manage library-owned sets; group administrators can manage sets owned by their groups.


Signal sets can be owned by a library or a group. When a signal set is owned by a library, it is available to all users in the library.

When a signal set is owned by a group, it is available to all users within the group. Users who are not part of the group cannot add signals from the signal set to a case, but they can view the signal set signals if an authorized user has added them to the case.


Signal sets can be enabled or disabled. When disabled, the signal set does not appear in the signal set tray. This prevents new signal nodes from the signal set from being added to a case.

Signal sets should be disabled if they are not currently in use / are deprecated.


Signal sets exist to organize signals. Signals can have colors, descriptions, and can be enabled/disabled. They also have order, which drives the order of signals within the signal set tray.


Signals have order within a signal set. This drives the order of signals within the signal set tray. If applicable, it should correspond to the order of the signals within the process they represent.

To reorder signals, click on the signal in the right panel and drag it to the desired position.


Select New Signal Set, enter its name and description, and choose the owner when that choice is available. Select Create. Then select the saved set to add its signals.


Select the set and change Enabled in its right-hand details panel. Save the change when prompted. This controls whether users can add new signals from the set; it does not remove signal nodes already in cases.


To delete a signal set, click the delete button in the bottom right corner of the signal set manager.


Signals must be contained within a signal set. All changes to signal configurations are within the context of a signal set inside of the signal set manager.

To create a signal, click the Add Signal button in the right panel of the desired signal set. Name the signal, and optionally add a description and color. Signals can also be created in either the enabled or disabled state.

The color selected here is the color of the signal when active in a case.


Use the edit icon beside a signal to change its name, description, color, or enabled state, then save the changes.


To delete a signal, click the delete icon next to the signal. This will remove the signal from the signal set. Note that signals may only be deleted for a not-in-use signal set.