When viewing the incident directly, what is the ''assigned to'' field value of a new Incident that was just reported to Cortex?
To pivot within a row to Causality view and Timeline views for further investigation, you can use the Open Card and Open Timeline actions respectively. The Open Card action will open a new tab with the Causality view of the selected row, showing the causal chain of events that led to the alert. The Open Timeline action will open a new tab with the Timeline view of the selected row, showing the chronological sequence of events that occurred on the affected endpoint. These actions allow you to drill down into the details of each alert and understand the root cause and impact of the incident.Reference:
Cortex XDR User Guide, Chapter 9: Investigate Alerts, Section: Pivot to Causality View and Timeline View
PCDRA Study Guide, Section 3: Investigate and Respond to Alerts, Objective 3.1: Investigate alerts using the Causality view and Timeline view
Moon
2 months agoCarrol
21 days agoPatria
24 days agoLettie
25 days agoNu
2 months agoElke
23 days agoScot
29 days agoTyra
1 months agoSvetlana
2 months agoOneida
2 months agoLigia
23 days agoAugustine
29 days agoLinette
2 months agoElke
2 months agoPhil
3 months agoEmilio
29 days agoSusy
1 months agoMarylin
2 months agoBen
2 months agoOretha
3 months agoJoanne
3 months agoOretha
3 months ago