Cases
A Case provides analyst the ability to group events together that may be linked to an incident. It also provides the ability for analysts to add notes, search event observables, create and track tasks, and provide a history of all actions related to the investigation.
Creating Cases
There are two ways to create a Case in Reflex: from Event cards and from the Cases page.
From Event Card
- Navigate to the Events page
- Select the relevant Event(s)
- Click the brief case icon located in the bottom left of the Event card
- Enter the necessary Case details
- Click
Create
From Cases Page
- Navigate to the Cases page
- Click
New Case
- Enter the necessary Case details
- Click
Create
Merging Events into a Case
This method requires you to merge the relevant Events into the case after its creation.
Merging Events into a Previously Created Case
- Navigate to the Events page
- Select the relevant Event(s)
- Click
# events
- Click
Merge into Case
- Search and select the appropriate Case
- Click
Merge