Skip to content
Release: Australia · Updated: 2026-05-25 · Official documentation · View source

Timeline in Security Incident Response Workspace

The timeline provides a chronological view of events related to a security incident. Events appear as point events or range events. Administrators can configure which events appear on the timeline and what details are shown in event popovers.

Point events appear as a single marker at a specific time. Range events appear as a bar spanning a duration, such as state transitions.

Base system timeline events

The base system provides 13 predefined event configurations.

NameEvent Type
ApprovalsPoint
Assignment Group ChangePoint
Capability ExecutionsPoint
Incident CreatedPoint
Incident ClosedPoint
Incident Re-assignedPoint
MITRE ATT&CK MappingPoint
MITRE D3FEND MappingPoint
Observable AddedPoint
Playbook ExecutionsPoint
State ChangedRange
Task ClosedPoint
Task OpenedPoint

Note: You can modify base system event configurations or create custom configurations to suit your organization's requirements.

Parent Topic:Configuring SIR Workspace

Related topics

Set up view of SIR Records

Configure SI design time investigation

SIR Workspace Related Records

Define the new Risk Score Calculator Rules

Configure Shift Handover

Security Incident Response conference call integration

Configure report templates in Security Incident Response

On-Call scheduling in Security Incident Response

Category management in Security Incident Response

View and update Security Incident Response system properties

Create quick filters for Security Incidents and Response Tasks lists