Incident management on the main tenant
Manage main tenant incidents in Cortex XSOAR 8.13 On-prem.
On the main tenant, you can create and make changes to content such as dashboards, incidents, and indicators, and propagate content to child tenants. You can view data from all your child tenants or pivot to each tenant to take certain actions.
On the Incidents page, you view and take action on incidents across all tenants. You can do the following:
Investigate an incident
When clicking on an incident you pivot to the child tenant where you take action on the incident. You can view a detailed summary, take action on the incident, add evidence, related incidents, etc.
Edit an incident
Edit system fields such as name, owner, severity, and custom fields. When you save the changes they are propagated to the child tenant.
Run a command
Sometimes you may need to run a command across all tenants.
Retention
You can mark multiple incidents for permanent retention.
Export an incident
You can export to a CSV file. By default, the CSV file is generated in UTF8 format.
Close/delete
Close or delete an incident.
For more information about incident management generally in Cortex XSOAR, see Incident management.
Note
You can't create incidents on the main tenant.
Although you can't investigate incidents directly, you can pivot to the incident on the child tenant by clicking the incident. You can also go to the child tenant's incident page by clicking main tenant (top left of the window) and selecting the relevant child tenant.
By default, the Incidents page displays open incidents (from all child tenants) in the last seven days. You can filter this by changing the date and selecting the relevant tenant.
Last updated
Was this helpful?
