Update information in security incident related records
Edit related records for a security incident in Security Incident Response Workspace directly from the Related Records tab without having to leave the current context.
Before you begin
Limitations:
- You can't modify fields that are restricted by an access control list.
- Fields updated or added by system such as Updated aren’t supported for inline editing.
Role required: sn_si.analyst
Procedure
Navigate to Workspaces > Security Incident Response Workspace.
Open a security incident.
Select the Related Records tab.
Open the related records tab for which you want to update information.
For example, to update the associated observables records of a security incident, you would select Threat Intel and then select Associated Observables.
Select the fields to update.
Update the values of the fields.
Parent Topic:Working with Security Incident Records
Related topics
Security Incident Overview section
Security Incident Details section
Security Incident Response Tasks
Security Incident Response Other Records
Security Incident Response Post Incident Review
TISC integration within SIR Workspace
Reports in Security Incident Response
Collaborate using conference call or chat in Security Incident Response
Viewing incident details with a relationship graph