Incident details are a page in the interface that contains all of the information related to the incident, including the incident properties.
To view incident details:
The window with incident details is displayed.
The toolbar in the upper part of the incident details allows you to perform the following actions:
Incident details contain the following sections:
The summary section contains the following incident properties:
In the Similar incidents section, you can view the list of incidents that have the same affected artifacts as the current incident. The affected artifacts include both observables and affected devices of the alerts linked to an incident. The list contains incidents in any status.
By using the list, you can evaluate the degree of similarity of the current incident and other incidents. The similarity is calculated as follows:
Similarity = M / T * 100
Here, M is a number of artifacts that matched in the current and a similar incident, and T is total number of artifacts in the current incident.
If the similarity is 100%, the current incident has nothing new in comparison with the similar incident. If the similarity is 0%, the current and the similar incident are completely different. Incidents that have similarity of 0% are not included in the list.
The calculated value is rounded off to the nearest whole number. If similarity is equal to a value between 0% and 1%, the application does not round such value down to 0%. In this case, the value is displayed as less than 1%.
Clicking an incident ID opens the incident details.
Customizing the similar incidents list
You can customize the table by using the following options:
In the Alerts section, you can view the list of the alerts linked to the current incident.
By clicking an alert ID, you can open the alert details. You can also use the toolbar buttons to unlink alerts from the incident or assign the alerts to yourself.
In the Assets section, you can view the devices and users affected by or involved in the incident.
By clicking a user name or a device name, you can:
You can also click a device name to open the device properties.
By clicking a user SID or a device ID, you can:
You can also click a device ID to open the device properties.
In the Observables section, you can view the observables that relate to the alerts linked to the current incident. The observables may include:
By clicking a link in the Value or Data columns, you can:
In the History section, you can track the changes that were made to the incident as a work item:
See also: |