On the Issue card, you can see details of the selected issue and take actions on an issue.
The Issue card provides a full breakdown of an issue, helping you understand the root cause and take action through relevant evidence, remediation guidance, and response options.
The issue card supports full case investigation by retaining case context. Once you have finished reviewing an issue, close the card to return to the initial case investigation.
Each issue card adapts to the type of issue you’re investigating, surfacing the most relevant information and tools at every stage of the workflow. While layouts may vary, most issues share a common set of tabs designed to support triage, investigation, and resolution.
Tab | Description |
|---|---|
Overview | Displays a description of the issue and provides key information, including:
The Evidence section contains information to help you investigate the issue, such as the causality chain. NoteThis section is context-specific and shows data according to the issue context. |
Resolution | Displays recommended remediation actions, and pending, in progress, and completed actions. For more information, see Resolution actions. |
Issue Information | Displays a summary of the issue, such as issue details , indicators, and outstanding tasks. Some fields are informational and some can be edited. Includes the following sections (depending on the layout):
|
Technical Information | Displays an overview of the information collected about the investigation, such as indicators, email information, URL screenshots, etc. When you run a playbook, the sections are automatically completed. |
Investigation Tools | Enables you to take action on the issue, such as converting a JSON file to CSV and checking if the IP address is in CIDR. |
War Room | A comprehensive collection of all investigation actions, artifacts, and collaboration. It is a chronological journal of the issue investigation. Each issue has a unique War Room. For information, see Use the War Room in an investigation. |
Work Plan | A visual representation of the running playbook that is assigned to the issue. For more information, see Use the Work Plan in an investigation. |