Skip to main content

Threat CenterThreat Center Guide

Manually Create a Case

Create a case to start tracking your response to a threat and assign the case to the person responsible for responding.

You can create a case automatically using Correlation Rules or Automation Management playbooks or manually from an alert. When you create a case from an alert, the case is associated with the alert; alert attributes and related detection attributes are copied to the case.

  1. In an alert, click Create a case.

    threatcenter-alert-createacase.png
  2. Enter information about the case:

    • (Optional) Stage – Select a case stage. If you select Closed, under Closed Reason, enter the reason why you're closing the case.

    • (Optional) Queue – Assign the case to the case queue responsible for responding.

    • (Optional) Assignee – Assign the case to the person responsible for responding.

    • Priority – Select the case's priority: low, medium, high, or critical.

  3. Click Create. The case appears in the list under the Cases tab. When you select the associated alert, you are now automatically redirected to the case. This action is recorded in the case and alert history.