Documentation Center
AlienVault® USM Anywhere™

Creating New Investigation

  Role Availability   Read-Only   Analyst   Manager

AlienVault USM Anywhere enables you to create and manage your own investigation.

To create a new investigation

  1. Go to Investigations.
  2. In the upper right of the page, click New Investigation.
  3. A popup window displays.

    New Investigation popup window

  4. Enter the information in each field.
  5. Fields in the New Investigation popup window
    Field Meaning
    Title Name identifying the investigation.
    Intents Classify your investigation. It can be Delivery & Attack, Environmental Awareness, Exploitation & Installation, Reconnaissance & Probing, and System Compromise. See Intent for more information.
    Severity

    Severity of the investigation. Values are Low, Medium, and High.

    Status Status applied to the investigation. By default, it is Open and can not be changed. You can change it later to In Review or Closed. To learn more about changing the default Status setting. See Viewing Investigations Details for more information.
    Description (Optional.) Enter an investigation description.
  6. Click Save.
  7. Note: USM Anywhere automatically assigns every new investigation to the user who creates the investigation. To modify the assigned user, see Editing Investigations.