Skip to content
Release: Australia · Updated: 2026-07-09 · Official documentation · View source

Add closure information to a security incident

When a security incident is in the Review or Closed state, you can enter closure information.

Before you begin

Role required: sn_si.basic

Procedure

  1. If it isn’t already open, open the security incident you want to update.

  2. Select the Related Records tab.

  3. Fill in the fields, as needed.

    FieldDescription
    Create knowledge articleThe option to generate a knowledge article using the contents of the post incident report.
    Close codeThe close code that best describes the reason for closing the security incident.
    Closed by[Read only] Displays the user who closed the security incident.
    Closed[Read only] Displays the date and time the security incident was closed.
    Close notesHow the security incident has been closed, including lessons learned, resolution, and so on.
  4. Select any of the following tabs to further update the security incident: