Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Update information in security incident related records

Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.

Before you begin

Limitations:

  • You can't modify fields that are restricted by an access control list.
  • Fields updated or added by system such as Updated aren’t supported for inline editing.

Role required: sn_si.analyst

Procedure

  1. Navigate to Workspaces > Security Incident Response Workspace.

  2. Open a security incident.

  3. Select the Related Records tab.

  4. Open the related records tab for which you want to update information.

    For example, to update the associated observables records of a security incident, you would select Threat Intel and then select Associated Observables.

  5. Select the fields to update.

  6. Update the values of the fields.

Parent Topic:Working with Security Incident Records

Related topics

Security Incident Overview section

Security Incident Details section

SIR Workspace Orchestration

Security Incident Response Tasks

Security Incident Response Other Records

Security Incident Response Post Incident Review

TISC integration within SIR Workspace

Reports in Security Incident Response

Collaborate using conference call or chat in Security Incident Response

Viewing incident details with a relationship graph

MITRE attack and defend technique graph

View and filter the incident timeline