Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Topics Discussed

...

  1. In the Armor Management Portal (AMP), click Security.

  2. Click Incidents.

    Column

    Description

    ID

    This is the unique ID of the security incident.

    Start TimeThe time stamp of the first event of the incident.
    Summary

    A brief description of the incident found.

    Severity

    There are four severity types:

    • Low
    • Medium
    • High
    • Critical
    Tags

    Armor will "tag" a detection with Incident if it requires security attention, and is a potential threat.

    Events

    A count of events that triggered a detection or incident in the Armor correlation engine.

    Status

    The current status of the incident or detection.

    • If an incident has a corresponding ticket, then the status of the ticket will display.
    • If a detection does not have a corresponding ticket, then the status will display Closed.
  3. Expand the row to view the First and Last Event Date.

  4. Click Filters + Settings to filter the data that displays in the table.

    1. Filter by Severity, Tags, or Status.

      1. Click Apply Filters to save your changes.

    2. In Table Settings, you can customize the view of your table.

      1. Click Save Settings to save your changes.

...

Anchor
Close-a-Security-Incident
Close-a-Security-Incident
Close A Security Incident

...

Only Armor Support can close a security incident. However, after you have performed the troubleshooting tips suggested by Armor Support, simply enter a comment expressing your desire to close the ticket. Armor Support will verify and confirm that the security incident has been properly addressed, and then they will close the ticket.

Info

Anchor
Troubleshoot-the-Incidents-screen
Troubleshoot-the-Incidents-screen
Troubleshooting

If you do not see any data in the Incidents screen, consider that:

  • Your account does not have any security incidents to display.

    • Armor is responsible for adding security-related incidents to this screen.

  • You do not have permissions to view security incidents.

    • You must have the Read Security Alerts and Read Security Offenses permissions enabled to view security incidents in this screen. Contact your account administrator to enable this permission. To learn how to update you permissions, see Roles and Permissions.

...