Find an incident
- Open Security > EDR Incidents and confirm the company selection.
- Use Host to search for a host name or domain.
- Narrow by Company, Severity (High, Medium, or Low), or State (Not Started, Investigating, or Closed).
- Review #, Host, Company, Severity, Category, State, Mitigation, and Detected.
- Browse additional pages as needed. The list loads 20 incidents per server page.
- Select a row to open its detail panel. Use the row’s … menu for follow-up actions.
Understand the fields
Severity indicates the imported severity, while Category identifies the kind of detection. A missing value does not imply low risk. State tracks investigation progress: Not Started, Investigating, or Closed. Mitigation is a separate value. Do not treat Closed as proof that the threat was mitigated, or Mitigated as proof that the investigation is closed. The badges summarize mitigation as Auto Mitigated, Mitigated, or Not Mitigated. For an unfamiliar provider state, open the detail panel and read the full Mitigation text before deciding what happened. Badge wording alone can simplify a more specific provider state.Read incident details
The side panel can show:- Incident number, severity, host, company, state, mitigation, verdict, and categories.
- Host details: Host Name, Domain, IP Address, Agent Version, and Company.
- Incident Details: Severity, Verdict, State, Mitigation, Detected, Created, and Updated.
- Open in Acronis Console, when a provider link is supplied.
- Technical identifiers that your MSP can use to match the record.
Missing or unexpected results
Check the selected company, active filters, provider mapping, and import status with your MSP. Security integration unavailable can indicate missing provider availability or permissions; it is not a clean-security result. A loading error can leave earlier rows visible. Wait for a successful load before taking action, and recheck the company and incident identity after changing scope. If an open panel still shows a previous selection, close it and reopen the intended row. Company users should ask for investigation through the Home AI Assistant, then review and confirm the request. Include the incident number, host, company, severity, and date. For the optional row shortcuts, see follow up on EDR incidents.Frequently asked questions
Does Closed mean the incident is mitigated?
Does Closed mean the incident is mitigated?
No. State and mitigation are separate. Inspect both and confirm the provider’s investigation result.
Why is the list already filtered when I arrive?
Why is the list already filtered when I arrive?
A Dashboard link can preselect a State. Review the active filters or clear them before searching more broadly.
Can I resolve an incident or start a scan here?
Can I resolve an incident or start a scan here?
No. This page is a reader with follow-up shortcuts and available Acronis links. Use the authorized provider workflow for remediation.
Does opening the Acronis link grant access to its console?
Does opening the Acronis link grant access to its console?
No. You need separately authorized provider access. Company users can ask their MSP to investigate instead.