Investigate & Recover — Activity Log Tab
Introduction
The Activity Log tab (labeled Activity Log, not "Activity"), on the Investigate & Recover page for a Threat Detections event, is a full chronological audit trail of every action taken on the event, from initial detection through to closure. It shows an Add a comment box at the top, followed by chronological entries grouped by date, each with an action name, description, a Triggered by line, and a timestamp — for example, Restore User Access and Delete Snapshot entries with Triggered by: admin. It includes:
- Automated system actions (for example: Event severity updated to Delayed Lockout, Starting snapshot update, Severity automatically adjusted to Major — Confidence 70%).
- Administrator actions (for example: Restore user access success, Event closed as Unexpected but Not a Threat).
- The date and time of each action.
Adding Comments
A comment box at the top of the tab lets you add notes to the event record at any time. Comments are saved to the activity log and visible to all administrators who review the event. Use comments to document your investigation findings, decisions made, or escalation steps taken.
A closing comment can also be added directly from the Close Event wizard's Add Comment step, which is saved to this same activity log.
See also
- Closing Event — the Close Event wizard — Add a final closing comment when you classify and close the event.
- Threat Detections — Overview — Back to the Threat Detections feature page.