Skip to main content
The Incident Report turns the totals on the Command Dashboard into the records behind them. Click a number on the dashboard and the report opens already filtered to that number’s time range, workspaces, and slice of the data, so you can see which incidents were counted, how they were classified, and who reported them.
Incident Report page

Opening the report from the Command Dashboard

Every entry point carries your current dashboard time filter and workspace selection into the report. You never have to re-apply them.

From the Closed Incident Tracker

Closed Incident Tracker with linked donut and severity rows
Each severity row shows the count, its share of the total, and an arrow indicating that the row is a link. Rows are not clickable while the dashboard is still loading. The record count above the summary confirms what carried over, for example 336 available records · 336 in dashboard totals.
Classification Trends cards and tabs
  • Click the arrow on a classification card (True Positive, False Positive, Benign Positive, Undetermined) to open the report filtered to that classification.
  • Inside the By reason and By module tabs, click a row to add that reason or source to the filter as well.
Selecting a classification card filters the tabs in place without leaving the dashboard. Use the arrow button when you want the full report instead.

Reading the report

Header controls

Report filters

Below the header, four filters narrow the report further. Changing any of them reloads the report and updates the page address, so the filtered view can be bookmarked or shared.

Classifications

Pick any combination of True Positive, Benign Positive, False Positive, and Undetermined, or choose All classifications.

Severity

High, Medium, Low, Informational, or Not retained for records where severity was not kept.

Source

Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike, or SentinelOne.

Reason

The closure reason recorded by the analyst or agent, plus No reason recorded.
A summary line under the filters restates the exact period, the number of workspaces in scope, the source, and the reason currently applied.

Report summary

Report summary cards and closure chart
Below the cards, Recorded closures by day plots the same records as a stacked bar chart, one bar per UTC day, so you can see when activity clustered inside the period.

Workspace breakdown

A table repeats the same summary per workspace, so a provider managing many tenants can see which ones drove the totals without changing the workspace filter.

Incident list

Incident list with closure details
The list is paginated. Column layout persists between visits.
Rule navigation is available for Microsoft Sentinel and Microsoft Defender XDR incidents. CrowdStrike and SentinelOne incidents show a message instead.
Select Print / Save as PDF in the report header to generate a clean, branded copy for a customer or a compliance file.
Print options dialog
The printed report always contains your filters, the summary statistics, the closure chart, and the workspace breakdown. Select Include the incident list to append every matching closure record.
The incident list includes every record that matches your filters, not just the current page, and can add many pages to the output. Leave it unchecked for a summary report.
Your provider name appears in the footer of every page, alongside the generation timestamp in the header.

How the numbers are counted

The report shows the classification, severity, and title as they were when the incident was closed. Later edits in the source product are not reflected.
Each incident is counted once per UTC day. An incident closed, reopened, and closed again appears on each of those days in the chart, which is why closure records can exceed unique incidents.
Where the closure hour was kept but the exact minute was not, the time is marked (approx.). Where severity was not kept, the record shows Not retained. Choose Not retained in the Severity filter to see those records, as specific severity filters exclude them.
If the dashboard total is higher than the number of retained records, the report shows a notice explaining that only the available records are listed. The record count above the summary states both numbers.

Command Dashboard

The dashboard the report is launched from.

Incident Classifications

What each classification means and when to use it.

Incident Management

The workflow for triaging, investigating, and closing incidents.

Workbench Overview

What opens when you click an incident ID in the report.

Need help? Contact the ContraForce Support team at support@contraforce.com.