Creating Incidents

Note: Creating an incident, whether manually or by escalating an alert, requires the Create Incidents permission. For details on incident permissions and access, see Managing Access to Incidents.

Incidents can be created manually from the Incidents page, or by escalating an existing alert. See Escalating Alerts to Incidents for details on creating an incident from an alert.

To create a new incident:

  1. Navigate to ThreatStream Next GenSecurity Operations > Incidents.

  2. Click Create Incident in the top right corner of the Incidents page.

  3. In the Create Incident dialog, provide the following:

    • Title (required) — a descriptive name for the incident

    • Description (optional) — a summary of the incident context

    • Priority (required) — P1, P2, P3, or P4

    • Severity (required) — Critical, High, Medium, or Low

    • Assign To (optional) — defaults to Unassigned

    • Associated Alerts (optional) — search and select existing alerts to link to this incident

    • Tags (optional) — analyst-applied tags for categorization and filtering

  4. Click Create Incident.

    The incident is created and added to the Incidents board.