The Incident Snapshots Generator
Incident snapshots audit task is an investigation task in Security
Desk. You can use this task to search
for incident snapshot generation events performed in Security Center, and see which Security Center users triggered the incidents and
when.
Before you begin
Ensure you have the required
Incidents snapshots monitoring
privilege.
Procedure
-
From the Security
Desk homepage,
open the Incident snapshots audit task.
-
Set up the query filters for the report. Choose from the following
filters:
NOTE: To ignore a filter, leave it blank or turn it off.
- Entities
- Select one or more entities.
- Incident IDs
- Click Add (
) to enter a
specific incident ID.
- Events
- Select one or more incident event types.
- Time range
- Filter by time range. This filter applies to timestamps defined by
the Time range type. The range can be defined
for a specific period or for global time units, such as the previous
week or the previous month.
-
Click Generate report.