Skip to content
Release: Australia · Updated: 2026-05-25 · Official documentation · View source

View and filter the incident timeline

View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.

Before you begin

Role required: sn_si.analyst

Procedure

  1. Navigate to Workspaces > Security Incident Response Workspace.

  2. Open a security incident.

  3. Select the Timeline tab on the incident overview.

    The timeline displays all configured events in chronological order. Point events appear as individual markers, and range events appear as colored bars.

  4. Select any event to view its details in a popover.

  5. To filter events, use the event type filter to select or deselect specific event types.

    The timeline updates to show only the selected types. Filtering applies only to your current view.

Result

Note: If you do not see expected events, contact your administrator to verify the event configuration is active.

Parent Topic:Working with Security Incident Records

Related topics

Security Incident Overview section

Security Incident Details section

SIR Workspace Orchestration

Security Incident Response Tasks

Security Incident Response Other Records

Security Incident Response Post Incident Review

Update information in security incident related records

TISC integration within SIR Workspace

Reports in Security Incident Response

Collaborate using conference call or chat in Security Incident Response

Viewing incident details with a relationship graph

MITRE attack and defend technique graph