Create an investigation
Create an investigation to view multiple detections in a single timeline and map.
You can access the list of created investigations in the investigations view on
the Detections page.
Before you begin
- Users must be granted NDR module access and have limited-write privileges or higher to complete the tasks in this guide.
- Log in to the ExtraHop system through https://<extrahop-hostname-or-IP-address>.
- At the top of the page, click Detections.
- Click Actions from the lower-left corner of a detection card.
- Click Add to an Investigation....
- Select Add detection to a new investigation.
- Click Next.
- Type a name and add notes to the new investigation. You can also set the status of the investigation and assign it to an ExtraHop user.
- Click Create.
After the investigation name appears at the bottom of the
detection card, you can click the investigation name to view the timeline and map.
- To add a detection to the investigation, click Actions, and then click Add to an Investigation....
- To delete a detection from an investigation, click the delete icon (X) on the detection in the investigation timeline.
Create an investigation from a detection summary
You can add multiple detections to an investigation at the same time from a summary panel on the Detections page.
A summary panel appears when detections are grouped by
Type in Summary view on the Detections page.
To add a group of detections to an investigation from a detection summary, complete the following steps:
Next steps
If you created a new investigation, type a name, and add notes. You can also set the status and assign the investigation to an ExtraHop user. If you added the detections to an existing investigation, review the name, status, assignee, and notes to make sure they reflect your changes.
Thank you for your feedback. Can we contact you to ask follow up questions?