Logstail
Skip to Content

Contacts

The Contacts page is used to manage the people or teams that may need to be reached during security operations, incident response, escalation, and notification workflows.

A contact can represent an internal responder, SOC lead, system owner, compliance stakeholder, manager, external partner, or any other person who should be available from the SOAR workspace.

Where to find it

Contacts

Open the main navigation menu and go to:

Navigation path

SOAR
Contacts

Application route

/soar/contacts

What this page is used for

Use the Contacts page when your team needs a centralized contact directory for SOAR operations.

Maintain responders

Keep responder and escalation contact details up to date.

Track ownership

Store system owners and responsible teams.

Store contact details

Manage phone numbers, emails, and locations.

Update responsibilities

Adjust ownership when teams or roles change.

Support investigations

Quickly find contacts during active incidents.

Clean outdated data

Remove stale or unused contact records.

Page Overview

The Contacts page provides a searchable table of all contact records along with controls to create, edit, and delete entries.

Contacts Overview

The page includes:

Search contacts
Add new contacts
View contact table
Edit contact details
Delete contacts safely

Contact Table

The contact table provides a compact overview of stored SOAR contacts and their operational details.

Contact name
Phone number
Email address
Location or region
Operational notes
Row actions (edit/delete)

Heads up

On smaller screens, the Actions column may require horizontal scrolling to view edit and delete options.

Search Contacts

Use the search field to find contacts quickly without manually scanning the table.

Add a Contact

Use Add Contact to create a new SOAR contact record.

Create Contact

Name – clear person or team name
Phone – reachable number
Email – monitored mailbox
Location – region or responsibility
Notes – role, escalation scope, context

Good contact hygiene

Use clear naming like “Jane Doe — Windows Platform Owner” instead of vague entries.

Edit a Contact

Use Edit when contact information changes.

Delete a Contact

Use Delete when a contact is no longer relevant.

Caution

Before deleting, confirm that no workflows depend on the contact.

Typical Workflow

Security Notes

Do not store credentials
Avoid sensitive secrets
Use notes for context only
Review critical contacts regularly

Troubleshooting

Contact not visible

  1. 1

    Clear search field

  2. 2

    refresh the page

  3. 3

    Confirm contact exists

Cannot access page

  1. 1

    Check permissions

  2. 2

    Verify SOAR access

Best Practices

Use consistent naming

Standardize teams and roles to avoid confusion and obscurity.

Keep data current

Update contact details regularly to avoid alert loss and security gaps.

Add useful context

Include meaningful notes that communicate context and inform your team.

Remove stale contacts

Clear outdated entries.

Review regularly

Validate escalation contacts for proper operations.

Avoid sensitive data

Never store secrets on contact information.