Skip navigation
All Places > Products > RSA NetWitness Platform > RSA NetWitness Platform Online Documentation > Documents
Log in to create and rate content, and to follow, bookmark, and share content with other members.

Investigate: Add Events to an Incident in the Events View

Document created by RSA Information Design and Development Employee on Jan 30, 2020Last modified by RSA Information Design and Development Employee on Sep 8, 2020
Version 7Show Document
  • View in full screen mode

When conducting an investigation in the Events view, you can select one or more events and create an incident that is available for incident responders in Respond. When you create an incident, if access restrictions are in effect, you can view only incidents to which you have access. For example, when creating incidents from the Investigate view, analysts must assign the incidents to themselves to view them in the Respond view. You can also add events to an existing incident in Respond to which you have access.

Note: An administrator must configure the respond-server.incident.manage and investigate-server.incident.manage roles and permissions. For more information, see "Role Permissions" and "Manage Users with Roles and Permissions" in the System Security and User Management Guide.

  1. Go to Investigate > Events.
  2. In the Events view, select one or more events.
    Events Analysis page displaying the list of events
  3. Click Create Incident.
    The Create Incident dialog is displayed. Complete the information in the Create Incident dialog.
    Create incident from Event Analysis page
  1. Select the severity. The alert summary field is a pre-defined value which is auto-populated but can be edited if required.
  2. Type a name for the incident in the Incident Name field.
  3. From the Priority drop-down list, select a priority for the incident. For example, an incident may be critical, high, medium, or low priority.

  4. Select an assignee for the incident from the drop-down list. This list includes the built-in users that have access to Investigate as well as any custom users that have been added to your system. For example, this list might include users for admin, analyst, dpo, operator, and users for incident responders.

  5. From the Categories drop-down list, select one or more categories of events that apply to this incident.
  6. Click OK.
    An incident is created with the selected event in Investigate.
  1. To add one or more events to an existing incident, select one or more events, and then click Add to Incident.

  2. In the Add to Incident dialog, select the alert summary and severity, and select one or more open and existing incidents to which the incidents will be added. You can Search for an existing incident by Incident-ID or Incident Name. When ready, click OK. The event is added to the selected incidents and updated in Respond.

You are here
Table of Contents > Downloading and Acting Upon Results > Add Events to an Incident in the Events View