The incident table provides an overview of all created incidents.
To view the incident table:
In the main menu, go to Monitoring & reporting→Incidents.
If necessary, apply the tenant filter. By default, the tenant filter is disabled and the incident table displays the incidents related to all of the tenants to which you have access rights. To apply the tenant filter:
Click the link next to the Tenant filter setting.
The tenant filter opens.
Select the check boxes next to the required tenants.
The incident table displays only the incidents that were detected on the assets that belong to the selected tenants.
The incident table is displayed.
The incident table has the following columns:
Incident ID, name. A name and a unique identifier of an incident.
Created. Date and time when the incident was created.
Updated. Date and time of the last change, from the incident history.
Threat duration. Time between the earliest and the most recent events among all of the alerts linked to the incident.