Return excluded security artifacts to a case
After you have excluded artifacts from a list in a case, you can return them to the case you can continue to work on them.
Before you begin
The Threat Intelligence plugin must be activated to use Security Case Management.
Role required: sn_ti.case_user_write
Procedure
Open a case that contains artifacts that you previous excluded from a list that you want to return to the list.
Click the Case Artifacts related list.
Click the tab associated with the artifacts you want to return to the list.
Click the Artifact Filter drop-down list and select Excluded Artifacts.
Excluded Artifacts list
Select one or more artifact records that you want to return to the Include list.
From the Actions on selected items drop-down list, select Include.
Select artifacts and return them to the Include list
Click Include in the confirmation box.
The selected artifacts are removed from the list of excluded artifacts and returned to the list of artifacts included in the case.
Parent Topic:Security artifact exclusion and inclusion
Related topics