The investigation timeline brings vehicle alerts, telemetry events, and contextual data into a unified chronological view. It helps security analysts reconstruct incidents, uncover correlations, and understand what happened before, during, and after a detected threat.
The timeline supports in-depth investigation by connecting security alerts with vehicle signals, locations, and surrounding events in a single continuous view. Analysts can trace the vehicle’s activity, compare multiple events, examine the detection logic and supporting evidence, and explore related Digital Twin insights, helping them identify patterns, validate threats, and reach conclusions faster.

Analysts can compare up to five timeline events to identify correlations, simultaneous spikes, and threshold crossings, making related patterns and anomalies easier to detect.
.png)
Analysts can review the logic behind each alert, including its conditions, data sources, hit counts, and hit rates, making it easier to understand why the alert was triggered and validate its accuracy.

Analysts can explore related vehicle anomalies by category, last occurrence, and confidence level, providing broader context for the selected alert and supporting faster investigation.
