View your escalation policy
The Escalations page shows the rules that determine how Arctic Wolf® escalates a potential security incident.
- Sign in to the Arctic Wolf Unified Portal.
- In the navigation menu, click
Organization Profile > Escalations.
Escalation rules are listed in a table with these columns:- Escalation Types — The incident types that the escalation rule is about.
- Priorities — The priority level that determines when an incident is escalated.
For example, if the Priorities value in an escalation rule is High, then Arctic Wolf® will not escalate the incident if its current priority level is Medium.
- Sensors — If applicable, the source of an alert, which determines when an incident is escalated. If an escalation rule includes one or more sensor deployment IDs, then Arctic Wolf will only escalate the incident if the alert originated from any of the sensors listed.
- Escalation Levels — Persons assigned to respond to the incident.
- Optional: To narrow the list of escalation rules, use one or more of these filters:
- Search — Searches all fields.
Note: Asterisks are not required for wildcards. For example, if you enter high, your search results will include escalation types where the word "high" appears in any field. For example:
- All rules about incidents with a High priority.
- Escalation types containing the word "high." For example,
Potential Security Issue > High IOC Finding - Hash.
- Priority — Filters by priority level.
- Sensor — Returns escalation rules associated with the selected sensor.
- Contacts Involved — Returns escalation rules assigned to the selected contact.
- Search — Searches all fields.
- To view the details of a specific escalation rule, click View Details.