Working with the View Ticket Page

Working with the View Ticket Page

The View Ticket page lets you see all the details of a ticket. On this page, you can see all the details of a ticket. The View Details page also gives you the tools to block or unblock IPs, suspend users, and most importantly, communicate to the XDR SOC team about the ticket you’re viewing.

Communicating to the SOC team using this page is more efficient than contacting the team by phone.

Navigating to the View Ticket page

You can navigate to the View Ticket page two ways:

  • By clicking Intelligence > View Ticket in the left navigation menu. If you navigate this way, you'll have to enter a Ticket Id in the top right corner.

  • By clicking a row in the All Tickets table on the Alarms & Alerts page. If you navigate this way, the ticket you clicked is displayed.

To view the View Ticket page
  • Do one of the following:

    • To search for a ticket, click Intelligence > View Ticket, then type a Ticket ID in the top right of the View Ticket page.

    • To view a specific ticket, click a row in the All Tickets table on the Alarms & Alerts page. Then click View Ticket Details .

View Ticket BA.png
  1. Click to open Barracuda Assistant. For more information, see Barracuda Assistant.

  2. Click Respond to SOC to communicate to the SOC team about this ticket. See Responding to Alerts from the XDR Dashboard.

  3. Type the number of the ticket you want to display.

  4. Displays the ticket ID.

  5. Displays the subject line of the ticket.

  6. Displays the ticket type.

  7. Displays the impact of the ticket.

  8. Displays the status of the ticket.

  9. Displays the account the ticket belongs to.

  10. Displays the MITRE ATT&CK® Tactic attempted.

  11. Displays the MITRE ATT&CK® Technique attempted

  12. Displays the time the ticket was created.

  13. Displays the originating IP.

  14. Click to Block or Unblock the IP. For more information, see Blocking and Unblocking IP Addresses .

  15. Displays the targeted user, if applicable.

  16. Click to suspend a Microsoft 365 or Duo user. See Suspending Users.

  17. Displays the SOC analyst.

  18. Displays a description of the incident.