Kaspersky Next XDR Expert

Viewing the incident types table

To view the incident types table:

  1. In the main menu, go to Settings → Tenants.
  2. Click the name of the required tenant.

    The tenant's properties window opens.

  3. On the Settings tab, click Incident management.

    The Types tab is displayed with the incident types table.

  4. If you want to configure the incident types table, do any of the following:
    • Click the filter icon (The Filter icon.), and then specify and apply the filter criterion in the invoked menu.
    • To hide or display a column, click the settings icon (The Setting icon.), and then select the necessary column.

The incident types table contains the following information:

  • Name. Name of the custom or predefined incident type.

    The table contains the following predefined incident types:

    • Common

      By default, this type has the Yes value in the Default column.

    • Information gathering
    • Compromise
    • Unauthorized access
    • Malware attack
    • Phishing
    • Availability
    • Insider threat
    • Data breaches
    • Configuration error
    • Supply chain attack
    • Web application attack
    • Vulnerability exploitation
  • Active type. If the incident type is active, you will be able to select this type in the incident details window.
  • Default. When you create an incident, the default type is automatically assigned to it. Possible values:
    • True
    • False
  • Workflow. Incident workflow.
  • Tenant. Name of the tenant to which the incident type belongs.
  • Creation type. Way the incident type was created. Possible values:
    • Custom
    • Predefined
  • ID. Unique identifier of the custom or predefined incident type. By default, this column is hidden.
  • Description. Incident type description. By default, this column is hidden.

If necessary, you can create new incident types, as well as edit and delete predefined and custom incident types.