Cases

Cases help you investigate security incidents LogPoint SOAR detects. Cases are created automatically when a playbook is triggered and run. Each Playbook Action can be represented as a Case Item, so you and your colleagues are able to track and understand what happened through the course of an automated incident investigation.

After running a playbook, you can also use a case’s action details as your audit log. Action details list all the important historical details or data of the action.

Go to Investigation >> Cases from the navigation bar to open the Cases page.

_images/LP_SOAR_Cases.png

Cases page

You can perform the following actions from the page:

  1. Filter the cases displayed on the page from the Query Bar or from the Filters Panel.

  2. Investigate individual cases in a timeline of related events.

  3. Export the displayed results in the .csv format by clicking Export Data.

  4. Toggle the status of a selected case.

  5. View the details of a selected case.

  6. Add new tags and comments to a selected case.

Investigation


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support