Tag and comment events
Use the tag column to communicate with members of the security team about an event in an investigation. Tags and comments are viewable to any user with access to the investigation. You can use filters to view only tagged investigations or use the Search function to search for text in notes and comments.
To add a tag to an event:
-
Do one of the following:
-
Click the Investigations tab, open an investigation and click View Results.
-
Go to Investigations > Private Search. In the Private Search tab, click View Results.
-
-
Click the tag column next to the event. The Tag and Comment dialog opens.
-
Select a tag from the dropdown.
-
(Optional) Add a comment to the event.
-
Click Save. The tag and comment icons are displayed in the tag column.
To remove a tag from an event:
-
Click the tag column next to the event. The Tag and Comment dialog opens.
-
Click Delete and then click Confirm in the dialog that opens.
Viewing and filtering tagged events
Tagged events are displayed in the Investigations and Private Search tabs. Hover over a tag to see an overview of the tagged events in the investigation.
To use tags and notes to filter investigations:
Option | Description |
---|---|
Go to Investigations > Investigate |
|
Go to Investigations > Private Search |
|
Go to Investigations |
|
After you filter the investigations, you can copy the URL to send the filtered view a member of your team. |
Using tags to pivot to the events table
You can use a tagged event in the investigation dialog to quickly pivot to the Events table in an investigation. This function is available in the Dashboard, Investigations and Private Search pages. Click the tag icon in the tooltip.
The Events table will display the same number of events tagged in the investigation tooltip.