View response task information for a security incident
You can view response task information, such as task SLAs, risk score audits and outages associated with a security incident.
Before you begin
Role required: sn_si.basic
Procedure
If it is not already open, open the security incident for which you want to view response tasks.
Click the Show Response Tasks related link.
Click any of the related lists to view or add information for the security incident.
| Tab | Description |
|---|---|
| Tasks | Displays tasks already defined for the security incident. You can manually create a response task. |
| Response Tasks | Displays actions to be performed in response to the security incident. |
| Task SLAs | View or add active task SLAs that were defined for the security incident. |
| Risk Score Audits | An audit record for each instance of a risk score being changed. |
| Outages | View or manually add new outage records associated with the security incident. |
| Email Search | A list of records that holds search criteria to run queries on an email server, such as a Microsoft® Exchange Server (based on the implementation installed), and stores the results received. Note: if the Security Operations Integration- Email Search and Delete capability is not active, the Email Search related link is not displayed. |
Click any of the following related links to further update the security incident:
- Show Affected Items
- Show Related Items
- Show IoC
- Show Enrichment Data
- When you have completed your entries, click Submit.