Kaspersky Next XDR Expert

Creating incident workflows

The incident workflow allows you to manage incident lifecycle.

To create an incident workflow:

  1. In the main menu, go to Settings → Tenants.
  2. Click the name of the required tenant.

    The tenant's properties window opens.

  3. On the Settings tab, click Incident management, and then select the Workflows tab.
  4. Click the Create button.

    The Create workflow window opens.

    By default, each incident workflow contains predefined statuses Initial and Done. You cannot delete or edit these statuses.

  5. In the Name field, enter the name of the new workflow.
  6. If necessary, in the Description field, enter a workflow description or a comment.
  7. To add new statuses, in the Workflow section, click Add status.
  8. In the window that opens, specify the following settings:
    1. In the Status name field, enter the name of the new status.
    2. In the Category field, select one of the following status categories:
      • Initial
      • In progress
      • Resolved
      • Done

      The category determines the color of the status icon.

    3. In the Incoming transition field, select one or several incoming statuses.

      If you want to configure a transition from all statuses to the incoming statuses, select the Allow all statuses to transition to this one option.

    4. In the Outgoing transition field, select one or several outgoing statuses.

      If you want to configure a transition from the outgoing statuses to all statuses, select the Allow this status to transition to all statuses option.

    5. Click Add.

      The visualized workflow is displayed in the Create workflow window.

      If necessary, repeat steps 7-8e to add new statuses.

  9. In the Create workflow window, click Save.

The new incident workflow is displayed in the table.