You can close an incident if you know that it is a duplicate or you are not going to solve it. In other cases, you must not close incidents, as they need to be solved by MDR SOC analysts. MDR SOC analysts resolve an incident if the measures that they recommended within this incident are applied. A resolved incident automatically closes after 72 hours.
To close an incident:
The incident list opens.
The incident page opens.
There is no Close incident button for incidents with the Closed status.
The Close incident block appears.
Select the True positive option if Kaspersky Managed Detection and Response detected a threat, but you do not want MDR SOC analysts to investigate and solve the incident.
Select the False positive option if Kaspersky Managed Detection and Response detected a non-threatening activity as a threat. Kaspersky Managed Detection and Response uses this information for improving the automated detection algorithms.
The Close incident block disappears.
The incident is closed. From now on, Kaspersky Managed Detection and Response will perform no actions in relation to this incident.
Page top