Step-by-step workflow guide for investigators
Discourse Monitoring
Who is this for?
What is on this page?
How to use this page?
New to Monitor?
A note on results
Before you start:
First steps
- Cast a wide net first and refine later. False positives are acceptable early on.
- Identify related organizations, key figures, and any known controversies before setup. These will become filters, not primary searches.
- If you're unsure what hashtags or terms the community uses, ask Echo before setting up the case.
Platform limits
- 4 hour-backfill only — when you create a new case, Monitor retrieves posts from the previous four hours only and cannot go further back.
- Max 5 languages per search – never leave language blank
- Filters narrow down your view of already collected messages, they do not affect how much data is pulled in.
- X, Instagram, Facebook, Snapchat have monthly caps
- Cases auto-pause — set to long enough to gather sufficient intel.
Access
- Open Maltego Monitor from maltego.monitor.com or app.maltego.com
Note that you need a Maltego ID to log in. - Make sure your plan includes access to Maltego Monitor (only Maltego Enterprise customers have Monitor included in their plans).
Resources
This guide assumes basic familiarity with Monitor. Feature names link to the documentation where needed. It helps to have the following pages open before you start:
Video Overview
Watch a real discourse monitoring case being set up in Monitor for the NASA Moon mission from scratch — searches, filters, and refinements included. Then follow the step-by-step guide below to build your own, or skip the video and jump straight to the steps.
To enlarge, double-click on the video.
Step-by-Step Guide
1. Set up your searches
| Search | Example Query | Key Notes |
|---|---|---|
| Primary topic |
"NASA Artemis" OR "moon mission" OR "moon landing"
|
|
| Related accounts |
@NASA @esa @AstroVictor
|
|
2. Refine and analyze
Once your case has been running for 24-48 hours, it is time to add filters to narrow down search results more effectively.
This section explains three refinement techniques: adding filters, working with the word count, and sentiment analysis for more targeted monitoring.
Add filters
Add related organizations, figures, and discourse topics as filters rather than standalone searches. This lets you see what is being said about them in the context of your topic, without creating a new search and pulling in all unrelated mentions. Include name variants and hashtag forms.
For the NASA mission, we can go with the following filters:
=Blue Origin= OR Bezos
"no women" OR women
Track the word count
Sentiment analysis
If the word count isn't informative, move to sentiment analysis in the same dropdown menu. It splits results into positive and negative sentiment.
Prioritise negative sentiment. This is where the emerging criticism, controversy, or hostility tends to emerge. Positive sentiment is worth reviewing, but treat negative as the primary signal.
Watch for unexpected associations. Review negative results for related figures or organizations that weren't in your original setup. If they appear consistently, add them as filters to track that thread specifically.
Optional steps
Track the most active posters
When filters are applied, identify who is most active in specific negative conversations. Consider adding them to a separate monitor to track ongoing behaviour.
Add a negative sentiment building block as a filter
Applying a general negative sentiment building block as a filter gives a broader view of critical discourse beyond specific flagged themes. Treat results as signals to investigate, not confirmed issues.
Other guides you might find useful:
Give us your Feedback!
Copyright © 2026
