When viewing the incident directly, what is the ''assigned to'' field value of a new Incident that was just reported to Cortex?
To pivot within a row to Causality view and Timeline views for further investigation, you can use the Open Card and Open Timeline actions respectively. The Open Card action will open a new tab with the Causality view of the selected row, showing the causal chain of events that led to the alert. The Open Timeline action will open a new tab with the Timeline view of the selected row, showing the chronological sequence of events that occurred on the affected endpoint. These actions allow you to drill down into the details of each alert and understand the root cause and impact of the incident.Reference:
Cortex XDR User Guide, Chapter 9: Investigate Alerts, Section: Pivot to Causality View and Timeline View
PCDRA Study Guide, Section 3: Investigate and Respond to Alerts, Objective 3.1: Investigate alerts using the Causality view and Timeline view
Ming
3 months agoDeane
3 months agoAhmad
3 months agoHerman
4 months agoHayley
4 months agoDesmond
4 months agoLina
4 months agoMeghann
4 months agoLewis
5 months agoAmber
5 months agoLinn
5 months agoMoon
5 months agoSueann
5 months agoCarla
5 months agoTequila
5 months agoVallie
5 months agoMoon
10 months agoCarrol
9 months agoPatria
9 months agoLettie
9 months agoNu
10 months agoElke
9 months agoScot
9 months agoTyra
9 months agoSvetlana
10 months agoOneida
10 months agoLigia
9 months agoAugustine
9 months agoLinette
10 months agoElke
10 months agoPhil
11 months agoEmilio
9 months agoSusy
9 months agoMarylin
10 months agoBen
10 months agoOretha
11 months agoJoanne
11 months agoOretha
11 months ago