---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Creating a Case and Linking from Investigation Canvas

# Creating a Case and Linking from Investigation Canvas {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use this section to create and link a case(s) from an investigation canvas.

## Before you begin

Role required: sn_sec_tisc.analyst

## Procedure

1. Navigate to WorkspacesThreat Intelligence Security Center.
2. Select Threat Analyst Workbench icon.
3. Go to Case ManagementAll Cases.  
   This displays all the cases.
4. Open any case record from the list.
5. Select Link Case from the Details section.  
   The Create and Link Case dialogue box appears.
6. Select a case from the list to associate the case to an investigation canvas.
7. Select Create New Canvas.  
   The Create New Case dialogue box appears.
8. Fill in the form fields, as appropriate.  
   {#tisc-link-case__table_fkk_wc1_zfc__entry__2}

   | Field | Description |
   |-|-|
   | Case ID | A unique identifier for the case. This is system generated ID. |
   | Short description | Summary of the request or issue that is being investigated or a short description. |
   | Case Type | Select the type of case being investigated. The possible options for the investigation are: * Threat Hunting * Request for Information * Vulnerability Management Case * Compliance Case * Incident Response Case * Collaboration Case * Others {#tisc-link-case__ul_p2m_tzv_pzb} |
   | Priority | Indicates the priority of a case. |
   | Assignment group | The assigned group responsible for working on the case. |
   | Status | The current status of the case. |
   | Assigned to | The analyst who is responsible for working on a case. |
   [ ]

   {#tisc-link-case__table_fkk_wc1_zfc}
9. Select Create and Link to create a new case and link it directly to the investigation canvas.  
   A confirmation is displayed confirming that the case is created and linked to the investigation canvas successfully.  
   Note:  
   This option is useful when no existing case is associated with the investigation canvas.
10. To remove a linked case, select the Unlink button.  
    For more information on how to directly link an existing case to the investigation canvas, see [Linking an existing case from Investigation Canvas](https://servicenow-prod.fluidtopics.net/1UsS_WRp1vgeq_fiDzJv_Q "Use this section to link an existing case from the investigation canvas.").
{#tisc-link-case__steps_b23_4wz_yfc}
**Related tasks**   

* [Creating an investigation canvas](https://servicenow-prod.fluidtopics.net/1HhM4WdIq0Dt81m4cclpuw "Create canvas to add observables from threat intelligence library.")

*[\>]: and then


