Hey! Thank you for reaching out. I can view the incident type I created (csirt - threat_activity_detection) within Settings > Incident Types. Regarding the Incident Type Matching Macro, if I click on the link with the setting for the incident type I created ("Click here to check your macro in action"), I do get results. FYI, the value in that box is 'eval incident_type = case( severity == "medium", "CSIRT - Threat_Activity_Detection")'
... View more