Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Viewing incident details with a relationship graph

Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.

Items related to a security incident could include associated observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related lists.

The following relationship graph example displays details for a security incident.

Image omitted: add-link-nodes-graph-sir.png
Relationship graph for a SIR incident.

When you open a relationship graph for a security incident, the available configurations are visible by default. You can interact with the graph as follows:

  • Zoom into any object fit into the screen and drag the nodes.
  • Add subnodes for each node, if available, and view details of the subnodes.
  • Hide any node or subnode from the graph.
  • View details of a subnode.

  • Customize a relationship graph
    Visualize and analyze security incidents and their associated data in a relationship graph.

  • Create a relationship graph for an incident
    Create a node relationship graph in Security Incident Response so you can better analyze a security incident by correlating it with malicious observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related information.

Parent Topic:Working with Security Incident Records

Related topics

Security Incident Overview section

Security Incident Details section

SIR Workspace Orchestration

Security Incident Response Tasks

Security Incident Response Other Records

Security Incident Response Post Incident Review

Update information in security incident related records

TISC integration within SIR Workspace

Reports in Security Incident Response

Collaborate using conference call or chat in Security Incident Response

MITRE attack and defend technique graph

View and filter the incident timeline