Creating custom incidents in MDR Web Console

Expand all | Collapse all

Creating custom incidents is not available in some of the commercial license tiers.

If you consider some activity in your infrastructure to be a threat but Kaspersky Managed Detection and Response did not create an incident automatically, you can add a new incident manually.

According to the terms of the service level agreement (SLA), the number of manually created incidents that are eligible for processing by the security team is limited. Information about the limitations is available on the MDR Usage tab in Kaspersky Security Center. On this tab, you can track the usage of the manually created incidents for the current period (for example, for the current week):

To add a new incident:

  1. In the MDR Web Console window, navigate to the Incidents menu item.

    The incident list opens.

  2. In the upper part of the window, click the Add button.

    The new incident block appears.

  3. Fill in the following fields:
    • Summary
    • Description
    • Assets
  4. If necessary, fill in the Tenant field.

    For the Tenant field, tenants that already exist in Console and the Root without tenants value are suggested.

  5. Click the Send button.

    The new incident block disappears.

The new incident is added to the incident list in MDR Web Console. You can view detailed information about this incident and the processing responses to it.

Page top