View and filter the incident timeline
View the chronological timeline of events for a security incident and filter by event type to focus on relevant activities.
Before you begin
Role required: sn_si.analyst
Procedure
Navigate to Workspaces > Security Incident Response Workspace.
Open a security incident.
Select the Timeline tab on the incident overview.
The timeline displays all configured events in chronological order. Point events appear as individual markers, and range events appear as colored bars.
Select any event to view its details in a popover.
To filter events, use the event type filter to select or deselect specific event types.
The timeline updates to show only the selected types. Filtering applies only to your current view.
Result
Note: If you do not see expected events, contact your administrator to verify the event configuration is active.
Parent Topic:Working with Security Incident Records
Related topics
Security Incident Overview section
Security Incident Details section
Security Incident Response Tasks
Security Incident Response Other Records
Security Incident Response Post Incident Review
Update information in security incident related records
TISC integration within SIR Workspace
Reports in Security Incident Response
Collaborate using conference call or chat in Security Incident Response