🌙
 

Subscribe to the Taegis™ XDR Documentation RSS Feed at .

Learn more about RSS readers or RSS browser extensions.

Event Details

events


Event Details are visible in search results, Investigations, and from Alert Detail panels. What details are displayed for each event vary by event type and available data.

Event Details for a Process Event

Event Details for a Process Event

When viewing tables of events, select an event title to view some of its essential details in a preview side panel. This allows you to continue browsing through the results table without losing your place or your filters. To view the full details of the event, select Open in a New Tab. The event details panel opens in a new tab.

Tip

Adjust the width of the preview side panel by holding and dragging it.

Event Details

Most events include:

NIDS Event Showing Netflow Diagram

NIDS Event Showing Netflow Diagram

JSON View in Event Details for an Auth Event

JSON View in Event Details for an Auth Event

Process Event Details

In addition to the above Event Details, process events include:

Data Types

Event Types

Create an Investigation From an Event

  1. At the top of the Event Details page, open the Actions drop-down and select Create New Investigation. The Create New Investigation dialog displays.

New Investigation

New Investigation

  1. Give the investigation a title and select a Priority and Type.
  2. Specify the Key Findings Template as blank or Security Investigation, then select Submit. The investigation is created.

Add an Event to an Existing Investigation

  1. At the top of the Event Details page, open the Actions drop-down and select Add to Existing Investigation. The Add Evidence to Investigation dialog displays.

  2. Select the investigation you want to add the event to, then select Submit.

 

On this page: