Incident Detail in Classic View

The Incident Detail (classic view) page provide more information about the incident to help you diagnose, contain, and remediate the threat. The page consists of the header, attack graph, and the following tabs: Overview, Detection, Response, Evidence, Worklog, and Report.

Note: The classic view is only displayed if the incident detail with AI analysis view is unavailable.

Click Launch AI analysis view in the upper right corner in incident detail to display the new AI-powered incident detail view. This view presents an overview of the AI analysis and evaluation of the incident, indicating whether it is likely a true or false positive threat. The Launch AI analysis view button is disabled for legacy incidents, including incidents that are directly promoted from Secure Cloud Analytics and incidents created using Cisco XDR APIs (for example, via an Automate workflow). For more information, see Incident Detail with AI Analysis. Click Classic view in the upper right corner to close the new view and return to the previous incident detail view.

Note: The AI analysis view is currently in Beta and subject to change.