Create Investigation

There are three ways to create an Investigation:

  • From the Investigations page

  • From the Reports page

  • From the Alerts page

Create an Investigation from the Investigations Page

To create an Investigation from the Investigations page:

  1. On the Investigations page, click the New Investigation button.

  2. The Investigation Details page opens where you have to document an Investigation.

Create an Investigation from the Reports Page

To create an Investigation from the Reports page:

  1. On the Reports page, click the Report name to open the Report Results page.

  2. On the Report Results page, click the Attach to Investigation or Attach to New Investigation icon .

    NOTE:

    You can attach either the entire Report or only selected events to an Investigation. To attach events, select checkboxes near the events, and then, click the Attach Event(s) to Investigation icon at the top of the page.

  3. If you attach the Report to the existing Investigation, in the Attach to Investigation dialog box, select the Investigation, and then select one of the following:

    • Attach—save the attached Report or events and remain on the Report Results page.

    • Attach and Edit—save the Report or events and navigate to the Investigation Details page.

  4. If you attach the Report to a new Investigation, in the Attach to New Investigation dialog box, enter a name of the Investigation, and then select Attach or Attach and Edit.

Create an Investigation from the Alerts Page

To create an Investigation from the Alerts page:

  1. On the Alerts page, go to the Alert you want to attach to an Investigation.

  2. Click the More Options icon , and then select Investigate.

  3. In the Alert Review dialog box, attach the Alert to the existing Investigation or create a new one.

    NOTE:

    When you attach the Alert to the existing Investigation, you have to be the owner of the Investigation. When you attach the Alert to a new Investigation, you can use Investigation Templates to automatically fill in some Investigation details.

  4. Enter the name of the Investigation, and then select one of the following:

    • Attach—save the attached Alert and return to the Alerts page.

    • Attach and Edit—save the attached Alert and navigate to the Investigation Details page.

    • Cancel—close the dialog box without creating an Investigation.