Skip to main content

How to close security events

This guide covers all you need to know about how to close open security events.

Daniel Sampson avatar
Written by Daniel Sampson
Updated this week

Once security events raised by our SIEM/SOC have been reviewed and investigated by you, they need to be closed to ensure that you have an accurate record of their outcome, which is a key requirement of compliance standards such as ISO27001 and PCI DSS.

Closing events in the my.defense.com platform is super straightforward - simply follow the steps outlined below.

Closing events from the security event view

  1. From the my.defense.com dashboard, select SIEM in the navigation on the left-hand side

  2. Next, select Security Events from the navigation sub-menu

  3. Locate the security event you wish to close and click View security event, which is located under the actions heading on the right-hand side

  4. Once you have reviewed the event and are happy to close it, select Close Security Event in the top right-hand corner

  5. Complete the Justification field - including details on why the event is being closed and what the outcome of the event was.

  6. Finally, select Security Incident or False Positive, and the event will be closed down.

Closing events from the threat view

  1. From the my.defense.com dashboard, select Threats from the navigation on the left-hand side

  2. Locate the threat you wish to close. You can filter by the type Security Event to view all open threats generated by our SIEM/SOC

  3. Click the View threat action button on the right-hand side

  4. Next, head to the Remediations tab

  5. Now select the remediation you wish to update by clicking the checkboxes and selecting either Remediated or False Positive from the status dropdown at the bottom of the page

  6. Once that's done, click Apply

  7. Next, you'll be asked to complete the Overview field - including details on why the event is being closed and what the outcome of the event was

  8. Once the overview is complete, select Submit, and the threat will be closed

Please note:

  • Closing a threat or security event will also close the threat/security event it's linked to.

  • Anything entered into the Justification or Overview fields will be included in your monthly SIEM report.

And that's it! You now know how to close security events πŸŽ‰

Did this answer your question?