Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

SIR Workspace Related Records

This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.

The following related lists groups that are available as a part of the base system. You can modify these groups or create groups within the application and their respective actions.

You can modify these groups or create new groups. For more information, see Configure Security Incident Related List on how to configure and group the related list for security incidents and response tasks. Each related list is fully functional within the SIR Workspace.

Related listGrouped item
Business Impact- Configuration Items - Affected Users - Related Configuration Items - Related Users - Affected Services
Threat Intel- Associated Observables - Threat Lookup Results
Phishing- Associated Phish Emails - Associated Phish Headers
Related Security Incidents- Parent Security Incident - Child Security Incident - Similar Security Incident
SLA RecordsTask SLAs
Source Events/AlertsSource events or alerts are the SIEM integration enabled related list such as Source Email, LogRhythm Drill Down Logs, LogRhythm Events, Aggregated IBM QRadar Offense and so on.Note: This list is completely dependent on the integration that you have in your instance. To view the relevant SIEM integration related list, you must install the latest version.
Sighting Search- Sightings Search Results - Sightings Search Details - Sighting
Observable Enrichment- Observable Enrichment Results - Associated MISP Events - MISP Enrichment Results
Endpoint Detection and Response \(EDR\)- Host Details - Running Processes - Running Services - Logged On Users - Network Statistics - Get File - Isolate Host Entries - Additional Actions On Endpoint - Microsoft Defender for Endpoint-Related Machines Details
Image omitted: sir-records.png
Related Records

Note: In general, you'd be able to create new records, link, or unlink existing records or new records against the related list group as applicable.

Parent Topic:Configuring SIR Workspace

Related topics

Set up view of SIR Records

Configure SI design time investigation

Define the new Risk Score Calculator Rules

Configure Shift Handover

Security Incident Response conference call integration

Configure report templates in Security Incident Response

On-Call scheduling in Security Incident Response

Category management in Security Incident Response

View and update Security Incident Response system properties

Create quick filters for Security Incidents and Response Tasks lists

Timeline in Security Incident Response Workspace

Configure Security Incident Related List

You can add new related lists or new related list groups, and modify existing groups or related lists that appear in the SIR Workspace.

Before you begin

The security incident related list are grouped and displayed as group related list items on the Related Records tab on the workspace.

Role required: sn_si.admin

Procedure

  1. In the classic UI, navigate to All > Security Incident > Show Open Incidents.
Image omitted: show-incidents.png
Open incidents
  1. Select any incident record.

  2. Right click on the incident context menu.

  3. Go to Configure > Related List.

Image omitted: configure-related-list.png
related list page
The **Configuring related lists on Security Incident form** is displayed.
  1. Go to View name and select New.

  2. Enter a name for the view.

  3. Select the newly created view.

    After you select the view, choose the required related list fields from the slush bucket.

Image omitted: related-list-slushbucket.png
related list slush bucket view
**Note:** If you want to modify anything, select the view and remove or add the items.
  1. Click Save.

  2. On the left navigation, navigate to All > Now Experience Framework > Experiences.

  3. Select Security Incident Response Workspace.

Image omitted: related-list-newexp.png
configure related list new experience
The **UX Application Security Incident Response Workspace** page is displayed.
  1. Go to UX Page Properties tab and select relatedListLayoutConfig option in the list view.
Image omitted: related-list-config.png
Related list
Image omitted: related-list-ux-view.png
Related List configuration section.
  1. Add the newly created view name separated by a comma to an already existing list of values in the Value text box under the sn_si_incident.viewsUsedForGrouping field.

    For example, if you had created a new view name as, Business Impact then in the Value text box you must specify it as business_impact (which is separated by underscore within the view name and separated by a comma after an existing value) under the sn_si_incident:groups field.

Image omitted: value-text-box-related-list.png
Related List Layout configuration.
**Note:** If you add the new view name under **sn\_si\_incident.viewsUsedForGrouping** field then the entry will be created in the **Related Records** tab of the workspace.

If you update the view name entry in **si\_other\_records.viewsUsedForGrouping** then the related list group will get added in the **Other Records** tab of the workspace.

Below is an example view which shows the newly created views added.
Image omitted: related-list-new-view-page.png
related list newly created view
**Note:** **requiredRolesForGrouping** contains comma separated sys\_user\_role record names. SIR Workspace user should have at least one of these roles, to use the grouped related lists. When a user does not have any of these roles then related lists view configured for the current user role using view rule configuration will be represented vertically without grouping. This property is ignored when **isGrouped** property is set to false. If this property is empty any user can access the grouped related lists.
  1. Click Save.

  2. Navigate to Workspaces > Security Incident Response Workspace.

  3. Select any specific security incident.

  4. Go to Related Records tab of the workspace.

    The grouped related lists are displayed.

Use this section to configure response tasks new related lists that appears on the Security Incident Response application.

Before you begin

Role required: sn_si.admin

About this task

The response tasks related list is not grouped but displayed as individual related list items, as there are few default lists. View the response tasks related items from the Response Tasks tab of the security incident record of the workspace.

Procedure

  1. Navigate to All > Security Incident > Response Tasks > Show All Tasks.
Image omitted: response-tasks-configure.png
List of all Security Incident Response Tasks
  1. Select any response task record.

  2. Select and hold (or right-click) the Security Incident Response Task context menu.

  3. Navigate to Configure > Related List.

    The Configuring related lists on Security Response Task form is displayed.

  4. Go to View name and select sirw view.

Image omitted: response-task-sirw-view.png
sirw view name highlighted
  1. Select the desired related list fields from the slush bucket.

    For example, Affected Locations.

Image omitted: response-tasks-selction.png
related list slush bucket view
  1. Select Save.

  2. Navigate to Workspaces > Security Incident Response Workspace > Response Tasks.

    The configured related lists (For example, Affected Users as selected) is listed within the Related Records list.

Image omitted: aafected-locations-response-tasks.png
configured related list