Track a detection
Detection tracking enables you to assign users, set a status, and add notes to a detection card.
You can also filter your view of detections by specific
status or assignee.
Before you begin
Users must have limited write privileges or higher to complete the tasks in this guide.You can change the assignee to any user in the system, add notes,
and set the status on a detection to one of the following:
- Open
- The detection has not been reviewed.
- Acknowledge
- The detection has been seen and should be prioritized for follow-up.
- In Progress
- The detection has been assigned to a team member and is being reviewed.
- Closed - Action Taken
- The detection was reviewed and action was taken to address the potential risk.
- Closed - No Action Taken
- The detection was reviewed and required no action.
Here are important considerations about tracking detections:
- The Acknowledged or Closed status does not hide the detection.
- The detection status can be updated by any privileged user.
- Optionally, you can configure detection tracking with a third-party system.
- If you are currently tracking detections with a third-party system, you will not see ExtraHop detection tracking until you change the setting in the Administration settings.
To track a detection, complete the following steps:
Track a detection from a detection card
You can track a detection by adding an assignee, status, and notes from a detection card.
To track a detection, complete the following steps:
Track a group of detections from a detection summary
You can apply a status, assignee, or note to multiple detections at the same time from a summary panel on the Detections page.
A summary panel appears when detections are grouped by Type in Summary view on the
Detections page.
To track a group of detections from a detection summary, complete the following steps:
Thank you for your feedback. Can we contact you to ask follow up questions?