Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.15.0

Investigate & Recover — Activity Log Tab

Introduction

The Activity Log tab (labeled Activity Log, not "Activity"), on the Investigate & Recover page for a Threat Detections event, is a full chronological audit trail of every action taken on the event, from initial detection through to closure. It shows an Add a comment box at the top, followed by chronological entries grouped by date, each with an action name, description, a Triggered by line, and a timestamp — for example, Restore User Access and Delete Snapshot entries with Triggered by: admin. It includes:

  • Automated system actions (for example: Event severity updated to Delayed Lockout, Starting snapshot update, Severity automatically adjusted to Major — Confidence 70%).
  • Administrator actions (for example: Restore user access success, Event closed as Unexpected but Not a Threat).
  • The date and time of each action.

Adding Comments

A comment box at the top of the tab lets you add notes to the event record at any time. Comments are saved to the activity log and visible to all administrators who review the event. Use comments to document your investigation findings, decisions made, or escalation steps taken.

A closing comment can also be added directly from the Close Event wizard's Add Comment step, which is saved to this same activity log.

See also