> For the complete documentation index, see [llms.txt](https://docs.enginsight.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.enginsight.com/docs/manual/english/platform-usage/siem/workflows.md).

# Workflows

Workflows allow you to define conditions based on [streams](/docs/manual/english/platform-usage/siem/advanced-settings/streams.md) that trigger an [incident](/docs/manual/english/platform-usage/siem/incidents.md) when they are met.

***

<i class="fa-compass">:compass:</i> Navigate to **SIEM** → **Workflows** to show a list of all created workflows. If you have not created any workflows yet, this view is empty.

<figure><img src="/files/EV5CYmQEMW4rXUUhfdCA" alt=""><figcaption></figcaption></figure>

The [workflow overview](#workflows-overview) provides information such as:

* the name of a workflow.
* the severity of a SIEM incident that is triggered by this workflow.
* whether the workflow is currently active.

You can also enable or disable workflows and [add new workflows](#add-a-workflow).

***

## Navigation

<i class="fa-magnifying-glass">:magnifying-glass:</i> Click the **Text Search** field above the list and enter a search term of your choice to find specific list items more quickly.

<i class="fa-computer-mouse">:computer-mouse:</i> Click the **Refresh** icon <i class="fa-arrows-rotate-reverse">:arrows-rotate-reverse:</i> above the list to update all list items.

<i class="fa-computer-mouse-scrollwheel">:computer-mouse-scrollwheel:</i> Scroll down the list or adjust the number of results shown per page ![](/files/2OyJnQuiS9EayPZHDbB3) to view additional entries. Use the page navigation ![](/files/IWrRD7h50XDr2neLTKmC) to switch between pages.&#x20;

### Filtering the List

<i class="fa-computer-mouse">:computer-mouse:</i> Click the **Filter** icon <i class="fa-filter">:filter:</i> above the list to filter the list by predefined parameters.

<details>

<summary>Available Filters</summary>

<table><thead><tr><th width="181.3984375">Parameter</th><th width="153.62890625">Type</th><th>Description</th></tr></thead><tbody><tr><td>Severity</td><td>String</td><td>Filter for all workflows with a specific severity, or exclude them from the results. All available severities are shown.</td></tr></tbody></table>

</details>

### Sorting List Items

<i class="fa-computer-mouse">:computer-mouse:</i> Click the **Sort** icon <i class="fa-sort">:sort:</i> next to a column name in the table header to sort by that column in ascending <i class="fa-angle-up">:angle-up:</i> or descending order <i class="fa-chevron-down">:chevron-down:</i> .

<i class="fa-computer-mouse">:computer-mouse:</i> Click the sort icon <i class="fa-bars-sort">:bars-sort:</i> above the list to adjust the priority of the applied sorting. A menu opens that shows all columns by which the list is currently sorted. Drag and drop the shown items to change the sorting priority.

### Further Actions for List Elements

<i class="fa-computer-mouse">:computer-mouse:</i> Select the checkbox <i class="fa-square">:square:</i> next to a list item to select the corresponding item. Alternatively, select the checkbox in the table header to select all list items.

The number of selected list items is now shown next to the search field.

The <i class="fa-slider">:slider:</i> **Actions** menu also appears in the upper-right corner. Click it to expand the corresponding submenu. The following actions are available:

<table><thead><tr><th width="209.06640625">Action</th><th>Description</th></tr></thead><tbody><tr><td>Delete</td><td><p>Delete all selected workflows.<br><br><i class="fa-computer-mouse">:computer-mouse:</i> Click <strong>Delete</strong> and confirm the message that appears by clicking <strong>Delete Permanently</strong>.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note</strong>: Deleted items cannot be recovered.</p></div></td></tr><tr><td>Enable</td><td><i class="fa-eye">:eye:</i> This action is only available if all selected workflows are inactive.<br><br>Enable all inactive workflows.</td></tr><tr><td>Disable</td><td><i class="fa-eye">:eye:</i> This action is only available if all selected workflows are active.<br><br>Disable all active workflows.</td></tr></tbody></table>

***

## Workflows: Overview

The workflow overview is structured as a table.

<figure><img src="/files/2yOIamJFo0gaeq6tvY3R" alt=""><figcaption></figcaption></figure>

The following information is shown:

<table><thead><tr><th width="200.22265625">Column</th><th>Description</th></tr></thead><tbody><tr><td>Name</td><td>Shows the custom name of the workflow and an additional description, if provided. The date and time it was created and it was last edited are also shown.</td></tr><tr><td>Severity</td><td><p>Shows the severity of SIEM incidents that are triggered by this workflow.<br></p><p>The following severity levels can be shown:</p><ul><li><strong>Informational</strong>: An incident triggered by this workflow is for informational purposes only.</li><li><strong>Low</strong>: An incident triggered by this workflow has a low criticality.</li><li><strong>Medium</strong>: An incident triggered by this workflow has a medium criticality. </li><li><strong>High</strong>: An incident triggered by this workflow has a high criticality.</li><li><strong>Critical</strong>: An incident triggered by this workflow has a very high criticality.</li></ul></td></tr><tr><td>Enabled</td><td>Shows whether the workflow is active and can trigger SIEM incidents.<br><br>An enabled workflow is indicated by a green <strong>check</strong> icon <i class="fa-circle-check" style="color:$success;">:circle-check:</i>. Disabled workflows are indicated by a red <strong>circle</strong> icon <i class="fa-circle" style="color:red;">:circle:</i>.</td></tr></tbody></table>

***

## Adding a Workflow

<i class="fa-computer-mouse">:computer-mouse:</i> Click <i class="fa-plus">:plus:</i> **Add Workflow** in the upper-right corner to [create a new workflow](/docs/manual/english/platform-usage/siem/workflows/add-workflow.md).

***

## Workflow: Edit View

<i class="fa-computer-mouse">:computer-mouse:</i> Click the name of a workflow to navigate to the corresponding edit view. There, you can adjust the [configured settings](/docs/manual/english/platform-usage/siem/workflows/add-workflow.md#general-settings) and delete the workflow.

The following actions are available:

<table><thead><tr><th width="200.39453125">Option</th><th>Description</th></tr></thead><tbody><tr><td>Save Changes</td><td><p><i class="fa-computer-mouse">:computer-mouse:</i> Click <strong>Save Changes</strong> after adjusting the settings.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note:</strong> Unsaved changes cannot be restored.</p></div></td></tr><tr><td>Back</td><td><i class="fa-computer-mouse">:computer-mouse:</i> Click <strong>Back</strong> to return to the list overview.</td></tr><tr><td>Remove</td><td><p><i class="fa-computer-mouse">:computer-mouse:</i> Click <strong>Delete</strong>, then confirm the prompt to remove all configured settings.</p><div data-gb-custom-block data-tag="hint" data-style="danger" class="hint hint-danger"><p><strong>Please note:</strong> Deleted settings cannot be restored.</p></div></td></tr></tbody></table>

***
