Skip to content

Commit 0a0e001

Browse files
Merge pull request #995 from yelevin/yelevin/incident-correlation
Incident resolution note
2 parents b2ff538 + 546630a commit 0a0e001

File tree

3 files changed

+10
-2
lines changed

3 files changed

+10
-2
lines changed

defender-xdr/manage-incidents.md

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -104,9 +104,17 @@ You can then save the resulting URL in your browser as a bookmark to quickly see
104104

105105
## Resolve an incident
106106

107-
Select **Resolve incident** to move the toggle to the right when an incident is remediated. Resolving an incident also resolves all the linked and active alerts related to the incident.
107+
When an incident is remediated and resolved, select **Resolved** from the **Status** drop-down list. Resolving an incident also resolves all the linked and active alerts related to the incident.
108108

109-
An incident that isn't resolved displays as **Active**.
109+
When you change an incident's status to **Resolved**, a new field is displayed immediately following the **Status** field. Enter a note in this field that explains why you consider the incident resolved.
110+
111+
:::image type="content" source="/defender/media/incidents-queue/resolve-incidents.png" alt-text="Screenshot of incident management panel with incident resolution note.":::
112+
113+
This note is visible in the activity log of the incident, near the entry recording the incident's resolution.
114+
115+
:::image type="content" source="/defender/media/incidents-queue/resolution-note-in-log.png" alt-text="Screenshot of appearance of resolution note in the activity log.":::
116+
117+
Resolving an incident also resolves all the linked and active alerts related to the incident. An incident that isn't resolved displays as **Active**.
110118

111119
## Specify the classification
112120

40.2 KB
Loading
28.5 KB
Loading

0 commit comments

Comments
 (0)