Skip to main content
Version: SIEM+ 1.0.4

Cases

Cases are the investigation workspace for alerts that need human attention.

Find a case

Open Cases and narrow the list with the available filters, including date, priority, impact, urgency, status, and description keywords. The page may limit the result to the first 500 cases; refine filters when you see that notice.

Select a case to open its details. Use the share action to copy a link that takes an authorized user directly to the case.

Work a case

On the case detail page you can:

  • read the description, alert context, tags, and history;
  • add comments for handoffs and investigation notes;
  • edit tags and use whitelist or blacklist context where available;
  • view AI-generated remediation and edit the remediation or implementation plan;
  • escalate the case with a required comment; and
  • close the case with a closing comment.

Closing a case records the action for later review. Some alerts can also be closed automatically when the account’s configured conditions are met.

Use the selected account

Cases are scoped to the selected account. Before sharing or closing a case, confirm the account selector in the header.