Generate and view correlation insights in the Security Incident Response Workspace to help you connect past events to the security incident you are working on.
Before you begin
Version 3.0 of Now Assist for Security Incident Response supports generating correlation insights from the Security Incident Response Workspace. See Supporting information for Now Assist for Security Incident Response for more information.
Roles required: sn_si.analyst, sn_si.manager or sn_si.basic
Procedure
-
Navigate to and open a security incident that is assigned to you.
-
Select the Investigation tab on the security incident record.
-
Select one or more filters that you want to base your correlation insights on.
You can select more than one observable.
- Associated Observables: Records that are linked by shared observables that suggest potential ongoing attacks or repeated use of malicious infrastructure. Examples might include IP
addresses, URLs, or file hashes.
- Configuration items (CI): Records that have the same CIs to help you identify potential vulnerabilities in specific systems. An example might be users' laptops.
- Affected Users: Past incidents that have the same users to help you see patterns such as frequent phishing attempts or multiple unauthorized access attempts. An example is a specific user’s
name.
A list of matching items is displayed.
-
Select the items from the list that you want to generate insights for.
-
Select Generate Insights.