Kaspersky Anti Targeted Attack Platform

Changing the status of an NDR event

You can change the following statuses of NDR events and aggregate events:

  • New. This status can be changed to In process or Resolved.
  • In process. This status can be changed to Resolved.

The Resolved status cannot be changed.

If the NDR event is associated with a risk, when assigning the Resolved status to this event, you can also change the risk status to Accepted.

To change the status of NDR events and aggregate events when managing the table of events:

  1. In the Network traffic events section in the table of events, select the NDR events or aggregate events whose status you want to change.
  2. Open the Change status drop-down list in the toolbar.
  3. In the drop-down list, select the command for the status that you want to assign.

    Some items of the drop-down list are not available in the following cases:

    • The In process item is unavailable if the selected items do not include NDR events or aggregate events with the New status.
    • The Resolved item is unavailable if the selected items do not include NDR events or aggregate events with the New or In process status.

    If all NDR events or aggregate events that satisfy the current filtering and search conditions are selected, and the number of selected items is greater than 1000, the application does not check their statuses. In this case, the In process and Resolved items are both available. However, the In process item can be used to assign the In process status only to events and incidents that have the New status.

    A window with a confirmation prompt opens.

  4. If the selected NDR events are associated with risks, and you want to simultaneously assign a status of Accepted to all these risks, select Assign the Accepted status for all risks related to the event if one event is selected or Assign the Accepted status for all risks related to the events if multiple events are selected.

    Risks may become associated with events when registering certain types of NDR events using the Asset Management technology.

  5. In the prompt window, click OK.