Creating a new case

Prev Next

There are three ways to create a new case:

  • Create a case on the Cases page and then manually add events.

  • Create a case from selected events.

  • Use an open alert and its corresponding events to create a new case.

To create a case on the Cases page:

  1. From the main menu, select Investigate > Cases.

  2. Click Create Case.

  3. In the Create Case dialog, enter a name and an optional description.

  4. Select the status of the case. For more information about statuses, see Understanding case details.

  5. Set the Priority and Classification for the case.

  6. (Optional) Choose an assignee for the case in the Assign to User drop-down menu.

  7. Click Create Case.

  8. Add events to the case as needed. For more information, see Adding events to an existing case.

To create a case using events:

  1. Run an indexed search for events you want to include in your case, as described in Searching the data.

  2. Select the checkbox next to the events you want to add to the case.

  3. Open the Groupby slider by clicking on the arrow icon.

  4. Click Add to Case.

  5. In the Create Case dialog, complete the fields to create the case, as described in the previous procedure.

To create a case from an alert and its associated events, see Adding alerts to cases.