General Layout
General Layout
The top bar
This menu contains all of the main functions of the site as a series of dropdown menus. These menus contain all (from the current user’s perspective) accessible functions sorted into several groups.
Simple User

- Home button: This button will return you to the start screen of the application, which is the event index page or the page the user set as custom home page using the star in the top bar.
- Event Actions: All the malware data entered into MISP is made up of an event object that is described by its connected attributes. The Event actions menu gives access to all the functionality that relates to the creation, modification, deletion, publishing, searching and listing of events and attributes.
- Dashboard: Allows you to create a custom dashboard using widgets.
- Galaxies: Shortcut to the list of MISP Galaxies on the MISP instance.
- Input Filters: Input filters alter what and how data can be entered into this instance. Apart from the basic validation of attribute entry by type, it is possible for the site administrators to define regular expression replacements and blocklists for certain values in addition to blocking certain values from being exportable. Users can view these replacement and blocklist rules here while an administrator can alter them.
- Global Actions: This menu gives you access to information about MISP and this instance. You can view and edit your own profile, view the manual, read the news or the terms of use again, see a list of the active organisations on this instance and a histogram of their contributions by attribute type.
- API: Links to the OpenAPI/Swagger reference for this instance’s API and to the built-in REST client.
- MISP: Simple link to your BASEURL
- Name: Name (Auto generated from Mail address) of current logged in user
- Envelope: Link to User Dashboard where you can consult some of your notifications and changes since last visit. Like some of the proposals received for your organisation.
- Log out: The Log out button to end your session immediately.
Admin User
* Home button: See description given earlier for user. * Event Actions: See description given earlier for user. * Dashboard: See description given earlier for user. * Galaxies: You can additionally update the Galaxies. * Input Filters: See description given earlier for user. * Global Actions: See description given earlier for user. * Sync Actions: With administrator access rights, shows a list of the connected instances and allows the initiation of a push and a pull. See sharing and synchronisation. * Administration: Administrators can add, edit or remove user accounts and user roles. Roles define the access rights to certain features such as publishing of events, usage of the REST interface or synchronization of any user belonging to the given role. Site administrators can also access a contact form, through which it is possible to reset the passwords of users, or to just get in touch with them via encrypted e-mails. * Logs: If you have audit permissions, you can browse the instance’s logs here (this menu was formerly called Audit). See the Logs section below. * API: See description given earlier for user. * MISP: See description given earlier for user. * Admin: User role. * Envelope: See description given earlier for user. * Log out: See description given earlier for user.
The left bar
The menu items in this menu bar are different depending on the current page you are on. The blue highlight shows you what page you are on.

* List Events: Lists all the events in the system that are not private or belong to your organisation. You can add, modify, delete, publish or view individual events from this view. * Add Event: Allows you to fill out an event creation form and create the event object, which you can start adding attributes. * List Attributes: Lists all the attributes in the system that are not private or belong to your organisation. You can modify, delete or view each individual attribute from this view. * Search Attributes: You can set search terms for a filtered attribute index view here. * List Collections: List collections — named bundles of events and other elements that can be managed and synchronised together. * List Event Reports: List the rich-text event reports on this instance. * List Analyst Data: List analyst data (notes, opinions and relationships) on this instance. * View Proposals: Shows a list of all proposals that you are eligible to see. * Events with proposals: Shows all of the events created by your organisation that has pending proposals. * List Tags: List all the tags that have been created by users with tag creation rights on this instance. * List Tag Collections: List all the tag collections that have been created by users with tag creation rights on this instance. Tag collections allow you to assign a collection of tags to an event or attribute in one action. * Add Tag: Create a new tag. * List Taxonomies: List all of the taxonomies installed on the MISP instance. This is also the place to activate the taxonomies as a Org Admin/Site Admin. * List Event Templates: List all of the event templates created by users with template creation rights on this instance. * Add Event Template: Create a new event template. * Export: Export the data accessible to you in various formats. * Automation: If you have authentication key access, you can view how to use your key to use the REST interface for automation here.
* List Galaxies: Index of 

* Import Server Settings: Import sync server configuration. * List Servers: Connect your MISP instance to other instances, or view and modify the currently established connections. * List Feeds: Follow the RSS feeds of other organisation or CERTs worldwide. * Search Feed Caches: Search for values potentially contained in the cached feeds and servers. * List SightingDB Connections: Allows you to manage existing SightingDB connections. SightingDB is an alternate sighting database that MISP interconnects with. * Add SightingDB Connection: Create a SightingDB connection. * List Communities: A list of communities that chose to advertise their existence to the general MISP user-base. * Cerebrates: Connect your MISP to one or several Cerebrate instances to act as lookup directories for organisation and sharing group information. * TAXII Servers: Configure TAXII 2.x server endpoints to push MISP data to. * Event ID translator: Allows to translate a local ID into the corresponding event ID on sync servers configured.