Evidence on Investigations

Role Availability Read-Only Investigator Analyst Manager

This section displays the alarms, events, and files associated with the investigation.

Important: You can link up to 100 alarms and 100 events to each investigation.

Evidence section on the details of a case investigation

You can click an alarm or an event to go to the alarm or event.

The asset name includes the icon if the asset is not in the system, or the icon if the asset has been added to the system.

Click the icon to access the following options. Your access to these options may vary based on your user role. See Role-Based Access Control (RBAC) in USM Anywhere for more information:

  • Add to current filter: Use this option to add the asset name as a search filter. See Searching Events for more information.
  • Find in events: Use this option to execute a search of the asset name in the Events page. See Searching Events for more information.
  • Look up in OTX: This option searches the IP address of the source asset in the AT&T Cybersecurity Alien Labs Open Threat Exchange® (OTX™) page. See Using OTX in USM Anywhere for more information.
  • Add asset to system: Use this option to create the asset in the system. See Adding Assets for more information.

Click the icon to access the following options. Your access to these options may vary based on your user role. See Role-Based Access Control (RBAC) in USM Anywhere for more information: