Creating a Case and Linking from Investigation Canvas
Use this section to create and link a case(s) from an investigation canvas.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Select Threat Analyst Workbench icon.
Go to Case Management > All Cases.
This displays all the cases.
Open any case record from the list.
Select Link Case from the Details section.
The Create and Link Case dialogue box appears.
Select a case from the list to associate the case to an investigation canvas.
Select Create New Canvas.
The Create New Case dialogue box appears.
Fill in the form fields, as appropriate.
| Field | Description |
|---|---|
| Case ID | A unique identifier for the case. This is system generated ID. |
| Short description | Summary of the request or issue that is being investigated or a short description. |
| Case Type | Select the type of case being investigated. The possible options for the investigation are:- Threat Hunting - Request for Information - Vulnerability Management Case - Compliance Case - Incident Response Case - Collaboration Case - Others |
| Priority | Indicates the priority of a case. |
| Assignment group | The assigned group responsible for working on the case. |
| Status | The current status of the case. |
| Assigned to | The analyst who is responsible for working on a case. |
Select Create and Link to create a new case and link it directly to the investigation canvas.
A confirmation is displayed confirming that the case is created and linked to the investigation canvas successfully.
Note: This option is useful when no existing case is associated with the investigation canvas.
To remove a linked case, select the Unlink button.
For more information on how to directly link an existing case to the investigation canvas, see Linking an existing case from Investigation Canvas.
Parent Topic:Working with Investigation Canvas
Related topics