Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Affected users in cases

You can create a new case from one or more affected users in the User [sys_user] table. You can also add users to existing cases.

  • Create a case from affected users
    You can create a security case from affected users in the User [sys_user] table. After the affected users have been used to create a new case, you can use Security Case Management to analyze the data.
  • Add affected users to existing cases
    You can add affected users to one or more existing cases. After the user records have been added to cases, you can use Security Case Management to analyze the data.

Parent Topic:Case creation from security artifacts

Related topics

IoCs and observables in cases

Security incidents in cases

Configuration items in cases