Close an investigation
You can close an investigation from the Investigations or Investigation Details pages.
To close an investigation:
- Select an investigation.
- Click the Status dropdown.
- Select Close.
- Select a Disposition.
- Click the Close Investigation button.
Apply allowlist rules
When you close certain investigations, you can add allowlist rules. Allowlist rules let InsightIDR know that it doesn’t need to open automatic investigations when it detects activity from the specified user or asset. Use an allowlist rule to prevent investigations from automatically opening for a specific asset or user in the future. The steps to create allowlist rules are different for ABA and UBA detection rules.
ABA detection rules and allowlisting
To allowlist assets or users for Attacker Behavior Analytics (ABA) rules, you need to create an exception.
- Navigate to Detection Rules > Attacker Behavior Analytics.
- Select a detection rule.
- Select the exceptions tab.
- Click the Create New Exception button.
- Enter the exception conditions.
- Name the exception.
- Optionally, add a note.
- Click the Create Exception button.
UBA detection rules and allowlisting
You can view modifications to User Behavior Analytics (UBA) rules by navigating to Detection Rules > Alert Modifications.
To allowlist an investigation:
- Select an investigation.
- Click the Close Investigation button.
- Select Allowlist and Close or Modify and Close.
- Select an allowlist rule or detection modification.
- Select a Disposition.
- Click the Apply Rule and Close or Apply Modification and Close button.
Bulk-close investigations
You can bulk-close investigations of the same type within a selected date range from the Investigations and Investigation Details screens.
To bulk-close an investigation:
- Select an investigation.
- Click the Status dropdown.
- Select Bulk Close.
- Select a Disposition to apply to all of the bulk-closed investigations.
- Click the Close Investigations button.
Reopen an investigation
Investigations can be reopened from either the Investigations home or Investigation Details pages.
To reopen an investigation:
- Select an investigation.
- Click the Status dropdown.
- Select Open.