Kaspersky Unified Monitoring and Analysis Platform

Viewing detailed incident data

In the incident window, you can view the details of an incident.

To view the details of an incident,

in the KUMA web interface open the Incidents section and select the incident.

An incident window opens with details of the incident. Some incident parameters are editable.

The top of the incident window displays a toolbar and the name of the user to whom the incident was assigned. In this window, you can process the incident: assign it to a user, combine it with another incident, or close it.

The Description section contains the following data:

  • Created—the date and time when the incident was created.
  • Name—the name of the incident.

    You can change the name of an incident by entering a new name in the field and clicking Save The name must contain from 1 to 128 Unicode characters.

  • Tenant—the name of the tenant that owns the incident.

    The tenant can be changed by selecting the required tenant from the drop-down list and clicking Save

  • Status—current status of the incident:
    • Opened—new incident that has not been processed yet.
    • Assigned—the incident has been processed and assigned to a security officer for investigation or response.
    • Closed—the incident is closed; the security threat has been resolved.
  • Priority—the severity of the threat posed by the incident. Possible values:
    • Critical
    • High
    • Medium
    • Low

    Priority can be changed by selecting the required value from the drop-down list and clicking Save

  • Affected asset categories—the assigned categories of assets associated with the incident.
  • First event time and Last event time—dates and times of the first and last events in the incident.
  • Type and Category—type and category of the threat assigned to the incident. You can change these values by selecting the relevant value from the drop-down list and clicking Save.
  • Export to RuCERT—information on whether or not this incident was exported to RuCERT.
  • Description—description of the incident.

    To change the description, edit the text in the field and click Save The description can contain no more than 256 Unicode characters.

  • Related tenants—tenants associated with incident-related alerts, assets, and users.
  • Available tenants—tenants whose alerts can be linked to the incident automatically.

    The list of available tenants can be changed by checking the boxes next to the required tenants in the drop-down list and clicking Save

The Related alerts section contains a table of alerts related to the incident. When you click on the alert name, a window opens with detailed information about this alert

The Related endpoints and Related users sections contain tables with host- and user data related to the incident. This information comes from alerts that are related to the incident.

The tables in the Related alerts, Related endpoints and Related users sections can be supplemented with data by clicking the Link button in the appropriate section and selecting the object to be linked to the incident in the opened window. If required, you can unlink objects from the incident. To do this, select the objects as required, click Unlink in the section to which they belong, and save the changes. If objects were automatically added to the incident, they cannot be unlinked until the alert mentioning those objects is unlinked.

The Change log section contains a record of the changes you and your users made to the incident. Changes are automatically logged, but it is also possible to add comments manually.