Security annotations
A security annotation is a note of explanation or comments added to a configuration item, observable, or use on a security incident.
Multiple security annotations are available for users and observables (requires the Threat Intelligence plugin). Reports on security annotations are also available.
- Create security annotations for CIs
Annotations on CIs allow you to track activity across incidents. You can add annotations to a single or multiple CIs. - Create security annotations for observables
You can select a single or multiple observables and apply security annotations to them using the Actions on selected rows choice menu. - Create security annotations for users
You can select a single or multiple users and apply security annotations to them using the Actions on selected rows choice menu. - View security annotations reports
The Security Annotations report presents details stored in the Security Annotations [sn_sec_cmn_security_annotations] table. You can customize the columns in the report and group the data in any way that suits you.
Parent Topic:Security Operations common functionality