In addition to automatic methods for creating security incidents, you can create them manually, as needed.

This video shows a visual overview of how you could create a security incident from the Security Incident list.

Before you begin

Role required: sn_si.basic

Procedure

  1. Navigate to any security incident list (for example, All > Security Incident > Incidents > Show All Incidents).
    Security incident lists
  2. Click New.
    New security incident
  3. On the form, fill in the fields.
  4. Right-click in the record header and select Save.
    If you added a new CI to the security incident, the following integration workflows are automatically executed:
  5. To view the information retrieved by these workflows, click the Show Enrichment Data related link, and then click any of the indicated tabs.
    Security Incident enrichment
    Note: Additional workflows are executed based on the third-party integrations you have activated as follows,

    Tanium Endpoint Platform integration: Tanium - Get Running Processes workflow