Events

The Events panel on the Investigation Results page displays data associated with the sightings in the investigation. You can sort and filter the list, and open the Event drawer to view the details of the events seen in the sightings.

Events Table

By default, the My environment events only check box on the Events table is enabled and checked to show only events in your environment, as indicated by the (Internal Event) icon. If the My environment only check box in the upper portion of the page is unchecked, you can uncheck the My environment events only check box to show all events (internal and external to your environment) in the Events table.

Note: If the My environment only check box is checked, the My environment events only check box becomes disabled and cannot be toggled to show all events (internal and external) because the page filter overrides the Events table filter.

Each row in the table includes data from the sighting in the investigation.

View Event Details in Drawer

When you click an event in the list, the Event drawer opens where you can quickly view the details. The drawer includes a summary of the event, timestamp for when it was first seen, severity, the reporting module and source, a short and long description, and the observables, assets, indicators, and relationships between observables in the event.

Event Drawer

Click the Source link to open the integration instance that reported it.

Click the (Pivot Menu) icon next to the observables, assets, or relations to view the disposition, observable type, and verdicts, and perform additional tasks by leveraging your integrated products. See the Pivot Menu help topic for more information.