Creating Domains
Use the Domain Management window to create domains based on JSA input sources.
Use the following guidelines when you create domains:
Everything that is not assigned to a user-defined domain is automatically assigned to the default domain. Users who have limited domain access should not have administrative privileges because this privilege grants unlimited access to all domains.
You can map the same custom property to two different domains, however the capture result must be different for each one.
You cannot assign a log source, log source group, or event collector to two different domains. When a log source group is assigned to a domain, each of the mapped attributes is visible in the Domain Management window.
You cannot assign a log source, log source group, event collector, or data gateway to two different domains. When a log source group is assigned to a domain, each of the mapped attributes is visible in the Domain Management window.
Security profiles must be updated with an associated domain. Domain-level restrictions are not applied until the security profiles are updated, and the changes deployed.
Create security profiles to define which users have access to the domains. After you create the first domain in your environment, you must update the security profiles for all non-administrative users to specify the domain assignment. In domain-aware environments, non-administrative users whose security profile does not specify a domain assignment will not see any log activity or network activity.
Review the hierarchy configuration for your network, and assign existing IP addresses to the proper domains. For more information, see Network Hierarchy.