> ## Documentation Index
> Fetch the complete documentation index at: https://docs.contraforce.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Incident Report

> Drill from the Command Dashboard into a filtered, printable report of every closed incident, with the summary, trend chart, workspace breakdown, and closure details behind each number.

The Incident Report turns the totals on the Command Dashboard into the records behind them. Click a number on the dashboard and the report opens already filtered to that number's time range, workspaces, and slice of the data, so you can see which incidents were counted, how they were classified, and who reported them.

<Frame>
  <img src="https://mintcdn.com/contraforce/7eCKFG28WsYKEaUd/images/incident-report/incident-report-overview.png?fit=max&auto=format&n=7eCKFG28WsYKEaUd&q=85&s=0890012d53ba4bfd3932ac7761f8c67a" alt="Incident Report page" width="2000" height="1046" data-path="images/incident-report/incident-report-overview.png" />
</Frame>

## Opening the report from the Command Dashboard

Every entry point carries your current dashboard **time filter** and **workspace selection** into the report. You never have to re-apply them.

### From the Closed Incident Tracker

<Frame>
  <img src="https://mintcdn.com/contraforce/7eCKFG28WsYKEaUd/images/incident-report/closed-incident-tracker.png?fit=max&auto=format&n=7eCKFG28WsYKEaUd&q=85&s=f1354a2a9f495d1f10ad17367308ef93" alt="Closed Incident Tracker with linked donut and severity rows" width="1094" height="764" data-path="images/incident-report/closed-incident-tracker.png" />
</Frame>

| Click                                                      | Opens                                                       |
| ---------------------------------------------------------- | ----------------------------------------------------------- |
| The **donut** (total closed incidents)                     | Every closed incident in the selected period and workspaces |
| A severity row: **High**, **Medium**, **Low**, or **Info** | The same report, pre-filtered to that severity              |

Each severity row shows the count, its share of the total, and an arrow indicating that the row is a link. Rows are not clickable while the dashboard is still loading.

The record count above the summary confirms what carried over, for example `336 available records · 336 in dashboard totals`.

### From Classification Trends

<Frame>
  <img src="https://mintcdn.com/contraforce/7eCKFG28WsYKEaUd/images/incident-report/classification-trends.png?fit=max&auto=format&n=7eCKFG28WsYKEaUd&q=85&s=fdf3f88f2e4fb844916450cb7f0b2f8e" alt="Classification Trends cards and tabs" width="2000" height="707" data-path="images/incident-report/classification-trends.png" />
</Frame>

* Click the **arrow** on a classification card (True Positive, False Positive, Benign Positive, Undetermined) to open the report filtered to that classification.
* Inside the **By reason** and **By module** tabs, click a row to add that reason or source to the filter as well.

<Tip>
  Selecting a classification card filters the tabs in place without leaving the dashboard. Use the arrow button when you want the full report instead.
</Tip>

## Reading the report

### Header controls

| Control                 | What it does                                                                               |
| ----------------------- | ------------------------------------------------------------------------------------------ |
| **Time filter**         | Changes the reporting period. Supports presets from 3 hours to 180 days, or a custom range |
| **Refresh**             | Re-runs the query with the current filters                                                 |
| **Print / Save as PDF** | Produces a print-ready copy of the report                                                  |

### Report filters

Below the header, four filters narrow the report further. Changing any of them reloads the report and updates the page address, so the filtered view can be bookmarked or shared.

<CardGroup cols={2}>
  <Card title="Classifications" icon="tags">
    Pick any combination of True Positive, Benign Positive, False Positive, and Undetermined, or choose **All classifications**.
  </Card>

  <Card title="Severity" icon="signal-bars">
    High, Medium, Low, Informational, or **Not retained** for records where severity was not kept.
  </Card>

  <Card title="Source" icon="plug">
    Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike, or SentinelOne.
  </Card>

  <Card title="Reason" icon="comment-question">
    The closure reason recorded by the analyst or agent, plus **No reason recorded**.
  </Card>
</CardGroup>

A summary line under the filters restates the exact period, the number of workspaces in scope, the source, and the reason currently applied.

### Report summary

<Frame>
  <img src="https://mintcdn.com/contraforce/7eCKFG28WsYKEaUd/images/incident-report/report-summary.png?fit=max&auto=format&n=7eCKFG28WsYKEaUd&q=85&s=d00c945701841cefabb73e9ab12f3a75" alt="Report summary cards and closure chart" width="2000" height="669" data-path="images/incident-report/report-summary.png" />
</Frame>

| Card                  | What it counts                                                           |
| --------------------- | ------------------------------------------------------------------------ |
| **Unique incidents**  | Distinct incidents, identified by workspace, source, and incident ID     |
| **Closure records**   | Individual closure events. One incident closed twice counts twice        |
| **By classification** | Closure records grouped by the classification recorded at closure        |
| **By severity**       | Closure records grouped by severity                                      |
| **By source**         | Closure records grouped by the detection module that raised the incident |

Below the cards, **Recorded closures by day** plots the same records as a stacked bar chart, one bar per UTC day, so you can see when activity clustered inside the period.

### Workspace breakdown

A table repeats the same summary per workspace, so a provider managing many tenants can see which ones drove the totals without changing the workspace filter.

### Incident list

<Frame>
  <img src="https://mintcdn.com/contraforce/7eCKFG28WsYKEaUd/images/incident-report/incident-list.png?fit=max&auto=format&n=7eCKFG28WsYKEaUd&q=85&s=9ae180a74fc54467ebcb8b262e68e597" alt="Incident list with closure details" width="2000" height="830" data-path="images/incident-report/incident-list.png" />
</Frame>

| Column                        | Description                                                                         |
| ----------------------------- | ----------------------------------------------------------------------------------- |
| **ID**                        | The incident ID. Click it to open the incident workbench                            |
| **Closed at**                 | Local closure time. Marked `(approx.)` when only the closure hour was retained      |
| **Title at closure**          | The incident title as it read when the incident was closed                          |
| **Workspace**                 | The tenant the incident belongs to                                                  |
| **Source**                    | The detection module that raised it                                                 |
| **Severity**                  | Severity at closure, or **Not retained**                                            |
| **Classification at closure** | The outcome recorded by the analyst or agent                                        |
| **Reason**                    | The closure reason, or **No reason recorded**                                       |
| **Rules**                     | **View rules** opens the detection rules behind Sentinel and Defender XDR incidents |

The list is paginated. Column layout persists between visits.

<Note>
  Rule navigation is available for Microsoft Sentinel and Microsoft Defender XDR incidents. CrowdStrike and SentinelOne incidents show a message instead.
</Note>

## Print or save as PDF

Select **Print / Save as PDF** in the report header to generate a clean, branded copy for a customer or a compliance file.

<Frame>
  <img src="https://mintcdn.com/contraforce/7eCKFG28WsYKEaUd/images/incident-report/print-options.png?fit=max&auto=format&n=7eCKFG28WsYKEaUd&q=85&s=b8de7f73399f677d54b2d9ca70b26559" alt="Print options dialog" width="947" height="572" data-path="images/incident-report/print-options.png" />
</Frame>

The printed report always contains your filters, the summary statistics, the closure chart, and the workspace breakdown. Select **Include the incident list** to append every matching closure record.

<Warning>
  The incident list includes every record that matches your filters, not just the current page, and can add many pages to the output. Leave it unchecked for a summary report.
</Warning>

Your provider name appears in the footer of every page, alongside the generation timestamp in the header.

## How the numbers are counted

<AccordionGroup>
  <Accordion title="Classification is recorded at closure">
    The report shows the classification, severity, and title as they were when the incident was closed. Later edits in the source product are not reflected.
  </Accordion>

  <Accordion title="Incidents can appear on more than one day">
    Each incident is counted once per UTC day. An incident closed, reopened, and closed again appears on each of those days in the chart, which is why closure records can exceed unique incidents.
  </Accordion>

  <Accordion title="Some closure details are not retained">
    Where the closure hour was kept but the exact minute was not, the time is marked `(approx.)`. Where severity was not kept, the record shows **Not retained**. Choose **Not retained** in the Severity filter to see those records, as specific severity filters exclude them.
  </Accordion>

  <Accordion title="Coverage notices">
    If the dashboard total is higher than the number of retained records, the report shows a notice explaining that only the available records are listed. The record count above the summary states both numbers.
  </Accordion>
</AccordionGroup>

## Related guides

<CardGroup cols={2}>
  <Card title="Command Dashboard" icon="gauge-high" href="/guides/getting-started/command-dashboard">
    The dashboard the report is launched from.
  </Card>

  <Card title="Incident Classifications" icon="tag" href="/guides/getting-started/incident-classifications">
    What each classification means and when to use it.
  </Card>

  <Card title="Incident Management" icon="octagon-exclamation" href="/guides/getting-started/incident-management">
    The workflow for triaging, investigating, and closing incidents.
  </Card>

  <Card title="Workbench Overview" icon="screwdriver-wrench" href="/guides/getting-started/workbench-overview">
    What opens when you click an incident ID in the report.
  </Card>
</CardGroup>

***

<Note>
  Need help? Contact the ContraForce Support team at [support@contraforce.com](mailto:support@contraforce.com).
</Note>
