SIR Workspace Related Records
This section consists of the related lists items that are grouped into sections such as associated observables and configuration items.
The following related lists groups that are available as a part of the base system. You can modify these groups or create groups within the application and their respective actions.
| Related list | Grouped item |
|---|---|
| Business Impact |
|
| Threat Intel |
|
| Phishing |
|
| Related Security Incidents |
|
| SLA Records | Task SLAs |
| Source Events/Alerts | Source events or alerts are the SIEM integration enabled related list such as Source Email, LogRhythm Drill Down Logs, LogRhythm Events, Aggregated IBM QRadar Offense and so on. Note: This list is completely
dependent on the integration that you have in your instance. To view the relevant SIEM integration related list, you must install the latest version. |
| Sighting Search |
|
| Observable Enrichment |
|
| Endpoint Detection and Response (EDR) |
|
Configure Security Incident Related List
You can add new related lists or new related list groups, and modify existing groups or related lists that appear in the SIR Workspace.
Before you begin
The security incident related list are grouped and displayed as group related list items on the Related Records tab on the workspace.
Role required: sn_si.admin
Procedure
Configure Response Task Related List
Use this section to configure response tasks new related lists that appears on the Security Incident Response application.