Creating Incidents

NOTE: To perform this function you must have user permission to create Incident(s).

This is useful in grouping a set of events together as a whole representing something of interest (group of similar events or set of different events that indicate a pattern of interest such an attack).

NOTE: If events are not initially displayed in a newly created Incident, it is most likely due to a lag in the time between display in the Real Time Events window and insertion into the database. If this occurs, it may take a few minutes for the original events to finally be inserted into the database and display in the incident.

To create an incident:

  1. In a Real Time Event Table of the Visual Navigator or a Snapshot Real Time Event Table, select an event or a group of events and right-click and select Create Incident.

image\ebx_-1555251106.gif

  1. In the New Incident Window, you may find the following tabs:

  1. In the Create Incident dialog box, enter:

  1. Click Create. The incident is added under the Incidents tab of the Sentinel Control Center.