Acting on a Case
You can take an Action on a Case from either the Cases > List View or single Case Drill Down View.
- From Cases > List View, select a Case, then click Actions and select an Action.
- From the same View, you can choose Actions > Drill Down and then choose an Action from that page.
Various Actions are enumerated below.
FortiAI: Click to send Case information to FortiAI for analysis. FortiAI must be configured for this feature to work.
Case Details: Open the Case Details sidebar to view case details. The default selection is Details.
- Details - Displays information about a case - Case ID, Severity, Risk, Risk Explanation, Organization, Summary, Incident ID, Assets, Status, Stage, Assignee, Created, Due, Elapsed. See Case Attributes for more information.
Note: If a certain detail does not exist, the attribute is not presented. For example, if a case was created with an event, and there is no incident, no Incident ID appears in the Case Details sidebar under Details.
-
Action History - Displays Case Action History, and Incidents Action History.
-
Actions - Click to access drop-down list of actions that can be taken.
-
Drill Down - Click Drill Down to access the Overview, Explore, MITRE ATT&CK®, Investigate, Notes, Evidence, and Action History tabs for enhanced analysis. See Viewing a Case in Depth for more information.
-
Display sidebar when selecting a case - Select if you wish for the Case Details sidebar to appear when a case is selected.
Drill Down: Click Drill Down to access the Overview, Explore, MITRE ATT&CK®, Investigate, Notes, Evidence, and Action History tabs for enhanced analysis. See Viewing a Case in Depth for more information.
Assign to...: Click to change the user assigned to the case by clicking Select, then selecting the user to assign the case to. You can use the GUI to select a group, then the user under FortiSIEM Analysts as well. The case due date can also be changed by clicking on the Due Date widget. When done, click Save.
Set Interested (Users): Click to configure users as Interested. If a user is set as Interested, and the Case Management Policy associated with the case includes notification for Interested Recipient(s), the Interested user(s) will receive notifications. To use, take the following steps:
- Click Select.
- Click on the user you wish to add as Interested, then click OK.
To add another user, click + and repeat steps 1 and 2. - When done, click Save.
Set Due Date:Set the case due date by taking the following steps.
- Click on the Due Date field.
- From the year and month drop-down lists, select the year and month.
- Select the day of the month.
- Select the Hour, minute, second, and AM/PM from the respective drop-down lists.
- Click on the Due Date field when done, and click Save.
Set Status: Choose one of the available options to set the Case status. For more information, see Status in Case Attributes.
- New
- Assigned
- In Progress
- Pending Customer Feedback
- Received Customer Feedback
- Closed
Set Stage: Choose one of the available options to set the Case stage. For more information, see Stage in Case Attributes.
- Detection
- Analysis
- Containment
- Eradication
- Recovery
- Lesson Learned
Set Severity: Choose one of the available options to set the Case severity. For more information, see Severity in Case Attributes.
- Critical
- High
- Medium
- Low
Set Case Management: Choose a case management policy to apply to the case using the Case Management Policy drop-down list and then click Save.
Add Note: Click to add a selected note to the case. In the Add New Note section, enter any text you wish to include about the case. When done, click Save.
For more information on features in Add Note, see here.
Add Attachment: To add an attachment to a note, click Choose Files, select your file(s) and click Upload.
- To select multiple files, hold down the Ctrl key while selecting files.
- The maximum size of a file attachment is 20MB.
- Existing attachments to a case can be found from the Drill Down Evidence tab.
Edit Summary: Click on the Summary field, and make any changes you need. When done, click Save.
Export Case: If you have any notes, add them to the User Notes field. To export the case as a PDF file, click Generate. After the report has been generated, click View to examine the case file.