Create an investigation
You can manually create an investigation from the Investigations page or the User and Accounts page in InsightIDR.
Investigate a user or an asset from the Investigations page
To create an investigation:
- From the InsightIDR left menu, select Investigations.
- Click the Create Investigation button.
- In the Enter Name field, provide the name of the investigation.
- Optionally, in the Select Assignee field, type and select the name of the user to whom you want to assign the investigation.
- In the Select Priority field, choose Critical, High, Medium, or Low.
- Click the Create Investigation button.
- Optionally, take action by using an automated workflow from multiple plugins or Insight Agent actions.
Once the investigation has been created, you can add data to your investigation.
Investigate a user from the User and Accounts page
To create an investigation:
- From the InsightIDR left menu, select Users and Accounts.
- Select a user category.
- Search for the user.
- Select Investigate [User Name]. The Create Investigation modal appears.
- Add an investigation name, date range, and other assets or users to the investigation.
- Click the Save button.
- Optionally, if you need more evidence, you can schedule endpoint queries to gather information for you.
- Optionally, take action by using an automated workflow from multiple plugins or Insight Agent actions.
Did this page help you?