Skip to main content

Threat CenterThreat Center Guide

Update Case or Alert Attributes

Update case or alert name, description, priority, and other attributes to reflect developments in your triage or response

In an case or alert, you can update the name, description, priority, MITRE ATT&CK® tactics and techniques, use cases, and tags. In a case, you can also assign the case to another stage, queue, and assignee. You can't update the User and Endpoint attributes, which are derived from detections. Any changes you make are recorded in the case or alert history.[7]

Update Any Case or Alert Attribute

Update a single attribute or multiple attributes at once.

  1. In a case or alert, navigate to the Overview tab:

    • To update a single attribute, for the attribute you're updating, click Edit.

      threatcenter-center-editattributes.png
    • To update multiple case attributes, click Edit Case Details.

      threatcenter-case-editcasedetails.png
    • To update multiple alert attributes, click Edit Alert Details.

      threatcenter-alert-editalertdetails.png
  2. Make your changes. Keep in mind:

    • For the description, you can enter up to 1,024 characters. To better communicate your message, you can format the text.

    • When you assign a case to a queue, you can only assign the case to an assignee who is a queue member. If you assign a case to a queue and the current assignee is not a queue member, the assignee is changed to Unassigned.

  3. Click Update. This action is recorded in the case or alert history.

Assign a Case Stage, Queue, or Assignee

Quickly assign a case to another stage, queue, or assignee.

When you assign a case to a queue, you can only assign the case to an assignee who is a queue member. If you assign a case to a queue and the current assignee is not a queue member, the assignee is changed to Unassigned.

You can also close multiple cases or alerts at once in the Cases tab.

  1. In the case, select the attribute.

    threatcenter-case-quickassign.png
  2. To search for a value, start typing.

  3. From the list, select a value. Your changes are saved. This action is recorded in the case history.

    If you change the case stage to Closed, in Type a reason, explain why you're closing the case, then click Close.




[7] MITRE ATT&CK and ATT&CK are trademarks of The MITRE Corporation ("MITRE"). Exabeam is not affiliated with or sponsored or endorsed by MITRE. Nothing herein is a representation of the views or opinions of MITRE or its personnel.