Linking an existing case from Investigation Canvas
Use this section to link an existing case from the investigation canvas.
Before you begin
Role required: sn_sec_tisc.analyst
Procedure
Navigate to Workspaces > Threat Intelligence Security Center.
Select Threat Analyst Workbench icon.
Go to Case Management > All Cases.
This displays all the cases.
Select Case Management > All Cases
Open any case record from the list view.
Select Link Case from the Details section.
The Link a Case dialogue box appears.
Select a case ID from the list to associate the case to an investigation canvas.
Image omitted: tisc-link-an-existing-case-from-canvas.png
Link an existing case from investigation canvas.
Link an existing case from investigation canvas.
A confirmation message is displayed confirming that the case is linked successfully.
**Note:** In case if no case is available for linking to the Investigation Canvas, you can create a new case to initiate and organize your investigation context. For more information on how to create a new case, see [Creating a Case and Linking from Investigation Canvas](tisc-link-case.md)
.
- To remove a linked case, select the Unlink button.
Parent Topic:Working with Investigation Canvas
Related topics