Fix the details for incidents in Monthly Summary Report [INCIDENT LOG]
C
Chris Bareham
Please add more of the summary to the incidents on the INCIDENT LOG page of the Monthly Summary Report. The current details are near useless beyond the date, severity, and number of alerts.
The Incident Log could be great, as it is meant to provide details about the number of alerts and a summary of each. However, each incident shows the top 3 lines of the report, much of the time is including the Huntress line of "The Huntress Platform will revoke all sessions, logging out the compromised identity from the tenant..."
This becomes useless for most of our customers, since the majority do not need or have access to the platform to click the "see more" and review the full report in the portal. I am not looking for copies of the full incident details on this page, but I would like to see more of the actual incident information or a cleaner summary that becomes useful.
Rather than seeing no valuable information ...
*** The Huntress Platform will revoke all sessions, logging out the compromised identity from the tenant environment in order to prevent attack spread. *** If you have an urgent request for support, please go to the link below to place a request a callback from SOC Support. h... (see more)
...Perhaps you could use the first paragraph of the Investigative Summary. If it adds more space to the Incident Log page, it is very minimal, but would be a clean summary on this page making it much cleaner.
Example
At 2026-04-08 19:21:41 UTC, Huntress detected that the user "john@example.com" successfully authenticated from datacenter infrastructure hosted by "Datacamp Limited" via the IP address 123.45.67.89. This autonomous system (AS) organization has high abuse potential and is known to host adversary infrastructure.
Photo Viewer
View photos in a modal