Skip to main content

Documentation Index

Fetch the complete documentation index at: https://help.dsalta.com/llms.txt

Use this file to discover all available pages before exploring further.

The Incidents page tracks security incidents across your environment — from detection through resolution. Incidents can be created automatically from connected integrations or logged manually.

How incidents are created

Incidents flow into DSALTA from two sources:
  • Integration-sourced — When you connect monitoring tools like Datadog, Grafana, or cloud providers (AWS GuardDuty, Azure Defender, GCP Security Command Center), open incidents sync automatically. Each record shows the integration name as its source.
  • Manual — Your team can log incidents directly in DSALTA. Manual incidents show Source: Manual.
Both types appear in the same table and are treated identically during audits.

Incident details

Each incident displays:
ColumnDescription
TitleName or summary of the incident
SeverityCritical, High, Medium, or Low
StatusOpen, Investigating, Contained, Resolved, or Closed
TypeSecurity breach, data exposure, service outage, unauthorized access, etc.
OwnerTeam member responsible for investigation and resolution
SourceIntegration name or “Manual”
CreatedWhen the incident was first detected or reported
Click any incident to view the full detail page with:
  • Timeline — Chronological log of all actions taken, status changes, and notes
  • Root cause — What caused the incident
  • Remediation — Steps taken to resolve and prevent recurrence
  • Affected assets — Which systems or data were impacted
  • Attachments — Supporting documents, screenshots, or reports

Working with incidents

To create a new incident manually, click + New Incident and fill in the required fields. Assign an owner and set the severity level. As your team investigates, update the status to reflect progress:
  1. Open — Incident detected, not yet investigated
  2. Investigating — Team is actively working on the incident
  3. Contained — Threat has been neutralized but resolution is in progress
  4. Resolved — Root cause addressed and systems restored
  5. Closed — Post-incident review complete, no further action needed
Each status change is logged with a timestamp and the user who made the change, creating a complete audit trail.

Integrations that feed Incidents

Connect these integrations to automatically sync incidents into DSALTA:
IntegrationWhat syncs
DatadogOpen and resolved incidents
GrafanaAlert-based incidents
AWS GuardDutyThreat findings and security events
Azure DefenderMicrosoft Defender for Cloud findings
GCP Security Command CenterSecurity findings and vulnerability alerts
To connect an integration, go to Integrations in the DSALTA sidebar.