Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Linking an existing case from Investigation Canvas

Use this section to link an existing case from the investigation canvas.

Before you begin

Role required: sn_sec_tisc.analyst

Procedure

  1. Navigate to Workspaces > Threat Intelligence Security Center.

  2. Select Threat Analyst Workbench icon.

  3. Go to Case Management > All Cases.

    This displays all the cases.

  4. Select Case Management > All Cases

  5. Open any case record from the list view.

  6. Select Link Case from the Details section.

    The Link a Case dialogue box appears.

  7. Select a case ID from the list to associate the case to an investigation canvas.

Image omitted: tisc-link-an-existing-case-from-canvas.png
Link an existing case from investigation canvas.
A confirmation message is displayed confirming that the case is linked successfully.

**Note:** In case if no case is available for linking to the Investigation Canvas, you can create a new case to initiate and organize your investigation context. For more information on how to create a new case, see [Creating a Case and Linking from Investigation Canvas](tisc-link-case.md)

.
  1. To remove a linked case, select the Unlink button.

Parent Topic:Working with Investigation Canvas

Related topics

Creating an investigation canvas