Secureworks CTP Master Ticket Closure Notice
Before you close a security incident created by a Secureworks CTP master ticket, you must verify that all child tickets associated with the master ticket are closed.
Before you begin
Role required: sn_si.admin
Procedure
Navigate to All > Secureworks Ticket Ingestion > Secureworks Ticket to Task.
The Secureworks CTP tickets with their corresponding security incidents are displayed.
Select on the security incident with the isGlobalParent field set to true.
Change the security incident State to Closed, specify the close codes and select Save.
Add a note requesting closure of the Master Ticket in Secureworks and select Submit Request.
The Master Ticket is now reassigned to the Secureworks SOC team.
Once the request has been submitted, you can close the security incident.
Navigate to Application > Module.