Skip to main content
The Incidents page tracks security incidents across your environment — from detection through resolution. Incidents can be created automatically from connected integrations or logged manually.

How incidents are created

Incidents flow into DSALTA from two sources:
  • Integration-sourced — Six integrations write to this page: Datadog, Grafana, ServiceNow, Sentry, Freshdesk and Honeybadger. Each record shows the integration name as its source.
  • Manual — Your team can log incidents directly in DSALTA. Manual incidents show Source: Manual.
Both types appear in the same table and are treated identically during audits.
Security findings from your cloud providers and code scanners — AWS, Azure, GCP, GitHub, GitLab — are tracked on Vulnerabilities.To manage one of those findings as an incident as well, log it with Create Incident and reference the finding ID in the description.

Incident details

Each incident displays: Type is captured on the incident itself but is not a column in this table. Click any incident to view the full detail page with:
  • Timeline — Chronological log of all actions taken, status changes, and notes
  • Root cause — What caused the incident
  • Remediation — Steps taken to resolve and prevent recurrence
  • Lessons learned — What your team would do differently next time
  • Breach — The data-breach categories recorded on the incident (PII, PHI, Financial, Credentials), shown as badges in the detail header
  • Attachments — Supporting documents, screenshots, or reports

Working with incidents

To create a new incident manually, click Create Incident and fill in the fields: Title, Description, Severity, Type, Status, Affected Data, Root Cause (optional), Remediation (optional), Lessons Learned (optional), Data Breach, and Detection Time. As your team investigates, update the status to reflect progress:
  1. Open — Incident detected, not yet investigated
  2. Investigating — Team is actively working on the incident
  3. Contained — Threat has been neutralized but resolution is in progress
  4. Resolved — Root cause addressed and systems restored
  5. Closed — Post-incident review complete, no further action needed
Each status change is logged with a timestamp and the user who made the change, creating a complete audit trail.

Integrations that feed Incidents

Six integrations sync incidents into DSALTA: To connect an integration, go to Integrations in the DSALTA sidebar.