The Active Directory group to move the account from or to. In the mandatory field Distinguished name, you must specify the full path to the group. For example, CN = HQ Team, OU = Groups, OU = ExchangeObjects, DC = avp, DC = ru. Only one group can be specified within one operation.
The Active Directory group to move the account from or to. In the mandatory field Distinguished name, you must specify the full path to the group. For example, CN = HQ Team, OU = Groups, OU = ExchangeObjects, DC = avp, DC = ru. Only one group can be specified within one operation.
Reset account password
Block account
Click Apply.
If required, create an incident based on the alert:
Click Create incident.
The window for creating an incident will open. The alert name is used as the incident name.
Update the desired incident parameters and click the Save button.
The incident is created, and the alert status is changed to Escalated. An alert can be unlinked from an incident by selecting it and clicking Unlink.
If you want to close the alert:
Click Close alert.
A confirmation window opens.
Select the reason for closing the alert:
Responded. This means the appropriate measures were taken to eliminate the security threat.
Incorrect data. This means the alert was a false positive and the received events do not indicate a security threat.
Incorrect correlation rule. This means the alert was a false positive and the received events do not indicate a security threat. The correlation rule may need to be updated.
Click OK.
The status of the alert is changed to Closed. Alerts with this status are no longer updated with new correlation events and aren't displayed in the alerts table unless the Closed check box is selected in the Status drop-down list in the alerts table. You cannot change the status of a closed alert or assign it to another user.