Kaspersky Next XDR Expert

Exporting information about incidents

You can export information about all incidents displayed in the incident table to a JSON file. This may be required when you have to provide this information to third parties.

To export information about incidents, you must have one of the following XDR roles: Main administrator, Tenant administrator, Junior analyst, Tier 1 analyst, Tier 2 analyst, SOC manager, Interaction with NCIRCC, Approver, or Observer.

To export information about incidents:

  1. In the main menu, go to Monitoring & reportingIncidents.

    The incident table is displayed.

  2. If necessary, group and filter the data in the table as follows:
    • Click the filter icon (The Filter icon.), and then specify and apply the filter criterion in the invoked menu.
    • Click the settings icon (The Setting icon.), and then select the columns to be displayed in the table.

    The filtered incident table is displayed.

  3. Click the Export button.
  4. In the window that opens, select the folder to save the JSON file, and then click the Save button.

If the operation is completed successfully, an appropriate message is displayed on the screen. Otherwise, an error message is displayed.