Viewing incident details with a relationship graph
Relationship graphs in the Security Incident Response workspace visually display the connections between a security incident and its related items to help you analyze the full context of a security incident.
Items related to a security incident could include associated observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related lists.
The following relationship graph example displays details for a security incident.
Relationship graph for a SIR incident.
When you open a relationship graph for a security incident, the available configurations are visible by default. You can interact with the graph as follows:
- Zoom into any object fit into the screen and drag the nodes.
- Add subnodes for each node, if available, and view details of the subnodes.
- Hide any node or subnode from the graph.
View details of a subnode.
Customize a relationship graph
Visualize and analyze security incidents and their associated data in a relationship graph.- Create a relationship graph for an incident
Create a node relationship graph in Security Incident Response so you can better analyze a security incident by correlating it with malicious observables, configuration items (CIs), similar security incidents (SIRs), response tasks, and other related information.
Parent Topic:Working with Security Incident Records
Related topics
Security Incident Overview section
Security Incident Details section
Security Incident Response Tasks
Security Incident Response Other Records
Security Incident Response Post Incident Review
Update information in security incident related records
TISC integration within SIR Workspace
Reports in Security Incident Response
Collaborate using conference call or chat in Security Incident Response