Viewing Incident Details

Note: Viewing an incident requires the View Incidents permission and at least Read access to that specific incident. For details, see Managing Access to Incidents.

You can view the full context of an incident, including its source alerts, related entities, activity history, and analyst comments, in the incident details panel or the dedicated full-page view.

To open the incident details panel, click the more options menu (...) for an incident in the list view and select View Details. You can also click the incident title directly.

The Incident Details panel provides a focused view of a single incident across three tabs: Overview, Activity, and Comments. Use these tabs to review source alerts and incident details, track lifecycle activity, and collaborate with your team without leaving the Incidents page.

Overview Tab

The Overview tab is the default landing tab. It gives you a summary of the incident metadata, its source alerts, and any case relationships that you may need to assess the incident before taking action.

The tab includes the following sections:

Section Name Description
Incident Summary Anomali AI-generated incident summary.
Agent

Incidents created by the Alert Triage Agent include the following fields:

Proposed verdict: Final action recommended by the Incident Response Agent after evaluating the alerts associated with the incident.

Incidents with the In Progress status require you to either accept the recommendation of the Agent, or submit an override action along with the note describing the reason for escalation.

  • Confidence: Percentage or qualitative score (for example, 90%) representing the Agent's certainty in its proposed verdict.

  • Analyst Note: (optional) add a note to the incident.

  • Evidence: Structured list of verified signals and data points (for example, intelligence hits, metadata matches) that support the investigation. This section is distinct from the reasoning, as it focuses on factual, cited data.

  • How I reached this decision: Agent reasoning.

  • Agent trace: Sub agents that evaluated data. Click the expand arrow of a sub agent to view its responsibility and finding.

Incident Details

Metadata displaying the following incident details:

  • Priority: Current incident priority badge (P1–P4)

  • Severity: Current incident severity badge (Critical, High, Medium, or Low)

  • Created: Relative timestamp of when the incident record was created

  • Last Updated: Relative timestamp of the most recent change to the incident record

Associated Alerts

Source alerts linked to this incident, with a count badge and an + Add Alerts button to link additional alerts.
The source alerts table includes the following columns:

  • Severity: color-coded severity badge for the alert

  • Alert Name: alert name as a clickable link to the Alert Details panel.

  • Status: current alert status.

  • Detections: count of constituent detections in the alert

  • First Seen: relative timestamp of the earliest constituent detection

Relationships Displays any case to which this incident has been linked. An incident can only be linked to one case. Click Open to open the linked case in a new tab and view the details of the case. See Viewing Case Details for more information.

Activity Tab

The Activity tab displays the Activity Log — a chronological, immutable record of all system and analyst events on this incident. Each entry shows a color-coded dot, an event description, an event type badge, the author, and a relative timestamp.

Logged event types include:

  • Created—records when the incident record was first created and by whom

  • Alert—records when an alert is linked to the incident

  • Assignment—records when the incident is assigned to an analyst

  • Status—records a status transition, for example OPEN → ASSIGNED

Comments Tab

The Comments tab allows you to add notes and context to the alert record. A rich-text composer appears at the top of the tab that includes all the standard text formatting tools.

Click Submit to post a comment.

Each comment entry shows:

  • Author name and timestamp

  • The actual comment

  • Per-comment action icons: Reply () available on all comments and Edit () available only on your own comments.

Actions Menu

 Click the action menu and select Add to Case to add the incident to a case. For details, see Managing Incidents.

Opening the Full Incident Page

To open an incident in a dedicated full-page view, click the external link icon next to the incident title.

The full-page view expands the same Overview, Activity, and Comments tabs into a two-column layout: the Summary sidebar on the left and the tab content on the right.