Tag and comment events
Use the tag column to communicate with members of the security team about an event in an investigation. Tags and comments are viewable to any user with access to the investigation. You can use s filter to view only tagged investigations or use the Search function to search for text in notes and comments.
To add a tag to an event:
-
Do one of the following:
-
Click the Investigations tab, open an investigation and click View Results.
-
Go to Investigations > Search timeline. In the Search Timeline tab, click View Results.
-
-
Click the tag column next to the event. The Tag and Comment dialog opens.
-
Select a tag from the dropdown.
-
(Optional) Add a comment to the event.
-
Click Save. The tag and comment icons are displayed in the tag column.
To remove a tag from an event:
-
Click the tag column next to the event. The Tag and Comment dialog opens.
-
Click Delete and then click Confirm in the dialog that opens.
Viewing and filtering tagged events
Tagged events are displayed in the Investigations and Search Timeline tabs. Hover over a tag to see an overview of the tagged events in the investigation.
To use tags and notes to filter investigations:
Option | Description |
---|---|
Go to Investigations > Investigate |
|
Go to Investigations > Search Timeline |
|
Go to Investigations |
|
After you filter the investigations, you can copy the URL to send the filtered view a member of your team. |