Skip to content

Create Ticket

Create Ticket

Purpose

Ticket is the primary means to record incidents, track progress, and coordinate response within SOC.

How to Create

  1. Manual: go to Tickets page → Create New Ticket.
  2. From Event: from Event Detail select Create Ticket (fields will pre-fill related information).
  3. Automated: SOAR workflow can automatically create ticket when conditions are met.

Important Fields

  • Title (required)
  • Office Name (required)
  • Agent Name (required)
  • IP/Source IP (required if related to network)
  • Content/Detail Message (required)

Attachment

  • Supports JPG/PNG/PDF files and log files as evidence.

Best Practices

  • Fill in complete context: timeline, impact, IOC (hash, IP, domain), steps already taken.
  • Assign Priority and Assignee immediately when creating to avoid handling delays.
  • If creating from Event, check and adjust pre-filled information before saving.