Kaspersky Next XDR Expert

Working with alerts on the investigation graph

On the investigation graph, you can perform the following actions with alerts:

Adding alerts to the investigation graph

You can add an alert to the investigation graph in one of the of the following ways:

  • From the general table of alerts that opens when you click the Add alert button on the investigation graph. You have to select the check boxes next to the alerts that you want to be displayed on the investigation graph, and then click the Show on graph button.
  • From the table of similar alerts.

To add an alert to the investigation graph from the table of similar alerts:

  1. Do one of the following:
    • If on the investigation graph you have an asset, observable, or segmentation rule, click its node, and then in the context menu, click Find similar alerts.
    • If on the investigation graph you have an event, click its node, and then in the context menu, click View details. In the window that opens, click the Show on graph button.
    • If on the investigation graph you have an alert, click its node, and in the context menu, click Events. In the table of events, click the event whose details you want to open. If the event details contain an observable, asset, or segmentation rule, click the link in the corresponding field, and then in the context menu, click Find similar alerts.
    • On the investigation graph, click the Threat hunting button, and then in the general table of events, click the event whose details you want to open. If the event details contain an observable, asset, or segmentation rule, click the link in the corresponding field, and then in the context menu, click Find similar alerts.

    The table of similar alerts is displayed.

  2. Select the check boxes next to the alerts that you want to be displayed on the investigation graph, and then click the Show on graph button.

The selected alerts are added to the investigation graph.

Hiding alerts from the investigation graph

You can hide an alert from the investigation graph in one of the following ways:

To hide an alert from the graph through the table of alerts:

  1. Do one of the following:
    • In the toolbar at the top of the investigation graph, click the Add alert button.
    • If you have observables, assets, or events nodes displayed on the graph, click the node for which you want to add an alert, and then in the context menu, select Find similar alerts.

    The table of alerts is displayed.

  2. Select the check boxes next to the alerts that you want to hide from the investigation graph, and then click the Show on graph button.

The selected alerts and their links will be hidden from the investigation graph. The related nodes remain on the investigation graph.

Changing an alert status

To change an alert status:

  1. Click the alert node, and in the context menu, select Change status.
  2. In the Change status pane that opens, select the status, and then click Save.

    If you select the Closed status, you must select a resolution.

The status of the selected alerts is changed.

Viewing the events related to an alert

To view events related to an alert, do one of the following:

  • Click the digit next to the alert node for which you want to display the events. The digit shows the number of events related to the alert.
  • Click the alert node for which you want to display the events, and then in the context menu, click Events.

If you want to add the events from the table to the investigation graph, select the check boxes next to the events, and then click the Show on graph button.

If you want to hide the events from the investigation graph, select the check boxes next to the events, and then click the Hide on graph button.

Viewing assets related to an alert

To view assets related to an alert, click the alert node.

In the context menu, the digits next to the Devices and Users items show the number of devices and users related to the alert.

If you want to add devices or users to the investigation graph, click the corresponding menu item.

Viewing observables related to an alert

To view observables related to an alert, click the alert node, and in the context menu, click Events.

In the menu that opens, the digits next to the items show the number of observables relate related to the alert.

If you want to add an observable (for example, Hash, Domain, IP address) to the investigation graph, click the corresponding menu item.