Create a case from CIs
You can create a security case from configuration items in the Configuration Item [cmdb_ci] table. After the CIs have been used to create a new case, you can use Security Case Management to analyze the data.
Before you begin
The Threat Intelligence plugin must be activated to use Security Case Management.
Role required: sn_ti.case_user_write
About this task
You need to navigate to the configuration items you want to use to create a case.
Procedure
Navigate to All > Configuration > Base Items > Computers to view CIs for computers.
The list for the selected CI type opens. From the list, you can create a new case from one or more CIs, or you can select a specific CI and create a new case from the form.
From the list, select the CIs you want added to a new case.
From the Actions on selected items drop-down list, select Add to Security Case.
Add a CI to a new case
The **Add to Security Case** dialog box opens. If you already have cases assigned to you, they display in the list.
Add a CI to a new case
Click Create New Case.
Fill in the fields.
Field Description Case Name Enter a name for this case. Description Enter a description that would be of value to the case analyst. Click Submit.
A message at the top of the list indicates that a new case has been created, along with a link to the case in Security Case Management.
Click the link to view the new case.
Parent Topic:Configuration items in cases
Related topics