Kaspersky Next XDR Expert

Predefined incident workflows

Kaspersky Next XDR Expert allows you to manage incidents by using the predefined incident workflow. In the incident workflows table, such workflow is named Standard. In the Creation type column, these workflows are marked as Predefined.

If necessary, you can edit the predefined workflow to customize it.

The table below shows the statuses of the predefined workflow, and the reasons why incidents switch to these statuses.

Status

Reasons

Initial

  • A new incident has been created (manually or automatically).
  • The incident status has been changed to Initial from one of the following statuses: In progress, On hold, or Done.

In progress

The user manually changed the incident status from Initial or On hold to In progress.

On hold

The user manually changed the incident status from In progress to On hold.

Done

  • The user closed the incident.
  • The user linked the incident to another similar incident that has not been closed yet.