Overview
Review both active and resolved cases in the Cases page.
This guide explains how to effectively navigate and utilize the Cases page features to quickly find the cases you need.
Customize the view
Click the customization icon on the right to switch between grid and list views. In list view you can customize which field columns are shown in case listings.
In list view you can use the Group by dropdown to select the grouping criteria. To present a complete list of all cases, you can select None.
Perform bulk actions
Select multiple cases for bulk operations like linking, assigning, changing severity or state, or exporting as CSV. The bulk action options will appear at the bottom of the screen.
Search for cases
The search feature on the Cases page helps you quickly locate specific cases using keywords. The free-text search queries fields such as the case title, case ID, description, and notes.
Location chips indicate where matches are located. Select a chip to view cases with matches in that specific location. For example, select the Notes location chip to view only cases where the search query is matched in the case note.
Applied filters are maintained during a search. Apply additional filters to further refine the displayed cases.
Utilize filters and sorting
Filter cases by severity, tags, assignee, MITRE tactic and technique, SLA and more, to quickly find exactly what you need.
Sort cases based on criteria such as creation time, resolution SLA, and more, and verify the sorting order (ascending or descending). The default sort is by severity from highest to lowest (descending).
Complete filters list
Complete filters list
You can filter cases by:
Access: Whether access is restricted to certain workspace users or groups.
Assignee: The user(s) that cases have been assigned to.
Category: Security category i.e. Application Security, Data Security, Malware, Identity Security etc.
Created: Creation date or period.
Custom fields: Any of the workspace custom fields.
Group assignee: The user group(s) that cases have been assigned to.
MITRE ATT&CK Tactic: Which MITRE ATT&CK Tactic has been identified.
MITRE ATT&CK Technique: Which MITRE ATT&CK Technique has been identified.
Resolution SLA: The percentage of the Resolution SLA that has elapsed.
Review conclusion: Reviewer verdict whether Approved, Rejected, or No conclusion (available only when Case review is enabled in Cases settings).
Reviewer: Which reviewer they have been allocated to (available only when Case review is enabled in Cases settings).
Severity: The severity of the case.
State: Which stage of the case management process cases have reached.
Tag: Which tags have been applied to cases.
Tasks: Whether cases have pending tasks.
Updated: Which date or period cases were updated.
Export filtered cases
Users who want to perform further analysis on cases outside Torq can export case data in CSV format.
Apply filters to view only the cases you are interested in, then export all the cases in your filtered view by clicking the Export all filtered cases icon in the top right of the page.
Depending on the number of cases you export, the CSV file may not be available immediately. Once it is, you will receive an email with a link to download it. The link is valid for one week.
Exports are limited to 10,000 cases and a maximum of 10MB sized files.
There may be minor formatting differences between the data exported using this method and data exported via the Export to CSV bulk action.
Employ views for quick access
Use saved views in the Cases page, with saved filter and sorting settings, for quick and convenient access to select sets of cases.
There are 3 types of views available:
Public views: User-created views, available to all users in the workspace.
Predefined views: Preconfigured public views built into the platform. They are not editable. The predefined views include sorting by severity in descending order.
All Cases: All the workspace cases.
High priority: Case severity is high or critical, and Resolution SLA is breached.
Pending tasks: Only cases with pending tasks.
Private views: User-created views, only available to the user who created them.
To create or modify public views, the cm.configuration.write scope is required. This scope is available to users with the Owner role.
To create or modify private views, the cm.case.write scope is required.
Manage cases with tags
Apply tags to cases to classify them by characteristics or required actions, improving search and case organization.
Add and remove tags
When adding a tag, you can select from the tags already used within the workspace (dropdown list) or type in a new one.
Filter by tags
Use the Tags filter and select one or more tags to filter by. Filtering by tag allows you to export all cases with specific tags without manually selecting each case.









