Incident Management (part 2)

 





To read part 1, please click here
To read part 3, please click here




Exploring the Full Details Page

As the name suggests, this page can show you lots of information about an incident like details on the alert(s) that make up the incident, any bookmarks associated with this incident, details on any entity, and any comments added to this incident. You can get to the Full Details page by simply clicking on the View Full Details button in the incident details pane, where the right side of the page is divided into the tabs that can show information about the alert itself, any bookmarks for this incident, the entities for this incident, and a  list of all the comments. Each of the sections are described below:
  • The Alerts Tab- This tab can show one or more alert(s) that make up an incident. There is a colored strip that shows the alert's severity. At the far right of this screen is the View playbooks link which can open a new pane showing all the playbooks. By clicking on the Run button in each playbook's row, you can run the playbook against the alert's information. 

  • The Bookmarks Tab- By clicking on it, you can view all the bookmarks associated with an incident. Search textbox can easily search any bookmark. The Create Time, Name, Created By, and Tags fields can seen for each bookmark. There is context-sensitive menu on the far right side on each listing with Remove from incident option which will ask for your confirmation to remove any bookmark.

  • The Entities Tab- It can show all the entities associated with an incident. Search textbox can search any entity whereas the ENTITIES filter helps you to select one or more Select All, Account, Host, IP, and/or URL. However, Select All is selected by default. ASSOCIATED ALERTS can help you to determine the total number of other alerts with the same entity.

  • The Comments Tab- This one will show all the comments related with an incident along with the total number of comments. You also add new comments while performing your investigation to remember your steps which can also help the others who want to look at the same incident or investigate one that is similar.     







To read part 1, please click here
To read part 3, please click here








Comments

Popular posts from this blog

Query, Visualize, & Monitor Data in Azure Sentinel

Planning for Implementing SAP Solutions on Azure (Part 2 of 5)

Work with String Data Using KQL Statements