Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Run Isolate Host

Isolate Host restricts system connections to other devices.

Before you begin

Role required: sn_si.analyst

About this task

Note: If no implementations are available, capability actions are not displayed in product menus.

The Security Operations Integration - Isolate Host or Endpoint flow can be triggered from the related list on a security incident.

Procedure

  1. Navigate to a security incident.

  2. Select Configuration Items from the Related List tab.

  3. Select Isolate Host in the Actions on selected rows... drop-down menu.

    The Isolate Host dialog box appears.

  4. Choose the implementation.

  5. Select Isolate Host.

    The flow execution audit is displayed in the work notes section.

Parent Topic:Security Operations Integration- Isolate Host capability