Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex SIEM
  • Getting started
    • All guides
      • Overview
      • Investigation management
      • Working with the investigations list
  • KQL reference
  • Access management

In this article:

  • Getting started
  • Creating an investigation
  • Updating an investigation
  • Renaming an investigation
  • Editing a description
  • Copying an investigation
  • Deleting an investigation
  1. Step-by-step guides
  2. Investigations
  3. Investigation management

Investigation management

Written by
Yandex Cloud
Updated at April 27, 2026
  • Getting started
  • Creating an investigation
  • Updating an investigation
    • Renaming an investigation
    • Editing a description
  • Copying an investigation
  • Deleting an investigation

Note

This feature is in the Preview stage. To get access, contact tech support or your account manager.

This section describes how to create investigations, manage their settings, and perform basic operations with them.

Getting startedGetting started

The Yandex SIEM section will appear in the Cloud Center interface as a Security Deck module after the access request is approved.

You need the ycem.editor role to use the service.

Creating an investigationCreating an investigation

To create an investigation:

Cloud Center UI
  1. Go to Security Deck.
  2. In the left-hand panel, select Yandex SIEM.
  3. Navigate to the Investigations tab.
  4. Click New investigation.
  5. Enter a name for your investigation in the header field.
  6. Under Description, add a description for your investigation.

Tip

Use clear names that reflect the investigation objective, e.g., Failed login analysis for February or Prod cluster suspicious activity.

Updating an investigationUpdating an investigation

Renaming an investigationRenaming an investigation

To rename an investigation:

Cloud Center UI
  1. Open an investigation.
  2. At the top of the page, click the investigation name.
  3. Enter a new name.
  4. Press Enter or click outside the input field.

Editing a descriptionEditing a description

To edit an investigation description:

Cloud Center UI
  1. Open an investigation.
  2. Under Information, click the Description field.
  3. Enter a new description.
  4. Press Enter or click outside the input field.

Copying an investigationCopying an investigation

To create an investigation copy:

Cloud Center UI
  1. Open an investigation.
  2. In the actions menu, select Create copy.
  3. Wait until the copy is created.

The copy inherits all requests and settings of the original investigation.

Deleting an investigationDeleting an investigation

To delete an investigation:

Cloud Center UI
  1. Open an investigation.
  2. In the actions menu, select Delete.
  3. Confirm the deletion.

Warning

Deleting an investigation is irreversible. All requests and results will be deleted.

See alsoSee also

  • Investigations
  • Queries
  • Working with the investigations list
  • Working with queries

Was the article helpful?

Previous
Overview
Next
Working with the investigations list
© 2026 Direct Cursus Technology L.L.C.