Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Security Incident Response- Get Network Statistics flow

The Security Incident Response > Get Network Statistics flow retrieves the network statistics for an affected Windows-based resource when added to a security incident in the Analysis state.

Before you begin

Role required: sn_si.analyst

About this task

For new security incidents that contain configuration items, the flow runs automatically when the state changes to Analysis.

Existing security incidents are automatically updated when you are in the Analysis state and you add a new configuration item.

Image omitted: get-network-statistics-flow.png
Get Network Statistics flow

The flow process actions include:

Procedure

  1. Open a security incident.

  2. Update the State to Analysis, if necessary.

  3. Add a configuration item (computer, server, or similar).

  4. Click Update.

    Security Incident Response Orchestration provides network statistics information in the Related Links > Security Incident Enrichments tab. For more information see, Security Operations enrichment data mapping.

    Actions specific to this flow are described here. For more information on other actions, see Common Security Operations integration flows and orchestration activities.

Parent Topic:Security Incident Response Orchestration workflows and activities

Parent Topic:Security Operations Integration- Get Network Statistics capability

Related topics

Create Lookup Request for IoC Changes workflow

Security Incident Response - Get Running Services workflow

Run procdump flow

Security Incident - Evaluate response task outcome workflow