Analyze incident links
Summary: You will use Event Link Analysis to explore one anchor incident's stored connections, compare pairs, and confirm or dismiss them, and create a case from a cluster.
Event Link Analysis is the anchor-based view: you pick a single incident and get a graph of that anchor surrounded by the incidents already stored as connected to it. Where the case network graph works inside a case, this works upstream of one.
How you get here
Event Link Analysis opens on a specific incident from two places: the Incident Connections review queue, and an incident's own detail page. There is also a research page, Entity Connection Research, whose only job is to pick the anchor: a searchable list of your organization's incidents with one search box (matching identifier, store number, city, state, or incident type). That picker has no navigation-menu entry and is reached by direct link only; the normal way in is from the review queue or an incident.
Read the graph
The anchor sits at the center with matched incidents around it. Links are drawn differently depending on whether they are confirmed, merely proposed, already within the same case, or within the same cluster; case groups and clusters are outlined as groups.
The graph is seeded from the anchor's already-stored connections, nothing is scored when the page opens. Only pairs the scoring rules already admitted exist here (a pair is stored at a score of 70 or more; a shared license plate alone scores 90). The minimum score control starts at 60 and filters that stored set, it never widens it, so setting it below 70 reveals nothing further. The current minimum score, filters, and search term are carried in the page address, so a particular view can be linked and shared.
Interactions
- Click a link to open an evidence pane with the full score breakdown per signal and the top reasons.
- Click a node to see the incident's details and a Compare action; Compare opens a side-by-side view, and confirming from there records a confirmed connection.
- Hover a proposed link for a dismiss control. A dismissed connection is permanent and excluded from the graph for that anchor from then on: there is no undo and no list of dismissed connections.
- A focus mode isolates a selected node and its direct connections.
The graph loads automatically when the page opens; there is no manual re-run: to take a fresh look, re-pick the anchor.
When the anchor has no matches at the current minimum score, the graph says "No similar events found with score ≥ N" and offers Try Another Event, rather than showing a blank page. An anchor with no stored connections at all stays empty at every setting.
Create a case from a cluster
A cluster framed on the graph offers Create Case from Cluster: the only place on the research page a case can be created. It opens a form pre-populated from the cluster (a name, a brief description, a narrative assembled from the member incidents, an estimated value, a case type defaulting to Booster Group, and a severity defaulting to Medium). Submitting creates the case, attaches every member incident, and carries the incidents' suspects over as case members marked AI-generated.