Actioning incoming tickets for EDR and SIEM

Actioning incoming tickets for EDR and SIEM

 

Todyl EDR and SIEM

 Low- and medium-priority will auto-close for logging purposes only.

High-priority and critical-priority tickets will generate an alert in the #todyl-high-alerts Slack channel. The email address for this channel is: todyl-high-alerts-aaaasgzgobx2iqkmarti4yzfae@nygg.slack.com


2/22/26: We will soon be moving non-SIEM customers to Datto EDR. EDR alerts for customers who remain on Todyl SIEM will be serviced by Todyl's NOC first. 

Datto EDR


Instructions to come. 
    • Related Articles

    • How to Communicate with Mission Control Regarding Tickets (Send, Assign or Inquire About Mission Control Work)

      Introduction Generally we handle help desk tickets internally. However, when we are overloaded, tickets should be "sent" to Mission Control, our help desk vendor. If you use the correct ticket template, it only takes a minute to edit the ticket so it ...
    • Creating Tickets: Best Practices

      Set the Category FIRST When creating a ticket or starting work on a new ticket which arrived via email, the first thing to do is to choose the category. Everything flows from the category. If you choose the correct category, you will be presented ...
    • How to Edit Recurring Tickets

      Search>Service Desk> Recurrence Master Tickets. Enter ticket number. Click the ticket. Go to Recurrence tab. First, you must make the edit(s) on the existing ticket recurrences. Under Instances, select (check off) off all the deferred tickets. Click ...
    • Creating Recurring Tickets and Service Calls

      What are Recurring Tickets? We use recurring tickets for scheduled maintenance that must be done on a recurring basis. The recurrence instances of each master ticket have a number appended. For example, if the master ticket is T20190528.0050, then ...
    • When to Use Tickets Vs. Tasks

      Tasks are used when both of the following are true: There is an Autotask Project in which the task can be created The work to be done in the task is not customer-facing (no appointment with customer).  If either of these is not true, you must use a ...