Alerts, cases and reports
From the first alert to the report the customer reads.
The queue, the investigation and the write-up are one workspace. Nothing is retyped between them.
Alerts
A queue you can actually work.
List or kanban
New, assigned, investigating, review, closed. Drag between stages or work the list with the keyboard.
SLA on every row
Acknowledge and resolve targets per organization and severity, on a 24x7 clock or the customer's business hours.
Quick preview
Open the essentials in a drawer without leaving the queue.
Event graph and process tree
See where the alert sits in the story and unfold what any node did next.
Correlations
Alerts become stories.
- Related alerts cluster on shared entities into one correlation with an entity risk score.
- Correlations escalate into cases with every member alert attached.
- Rule exceptions and suppressions are one right-click away from the queue.
Cases
The investigation workspace.
Timeline and tasks
Events, notes and actions on one timeline; a task list that is complete before the case closes.
Artifacts across the tenant
Indicators found in the case are checked against everything else the tenant has seen.
War room and roles
People, roles and @-mentions on the case, with attachments where the evidence needs a picture.
Categories with templates
Each case category carries its write-up structure and its task template.
Reports and tickets
What the customer receives.
- Reports are written from templates you define, with attached cases, a defanged indicator appendix and frozen dashboard captures.
- Print to PDF or publish a frozen copy straight to the customer portal.
- Monthly SLA reports are generated on schedule with attainment and volume.
- Customers raise tickets in the portal; analysts answer them from the console.
See XenXDR on your own telemetry.
A 30-minute walkthrough on fictional data, then a pilot in your environment. No slides, no pressure.