Changing an alert status

May 15, 2024

ID 221565

Expand all | Collapse all

As a work item, an alert has a status that shows the current state of the alert in its life cycle.

You can change alert statuses for your own alerts or the alerts of other analysts only if you have the access right to read and modify alerts and incidents.

If the alert status is changed manually, playbooks will not launch automatically. You can launch a playbook for such an alert manually.

An alert can have one of the following statuses:

  • New
  • In progress
  • Closed
  • In incident

To change the status of one or several alerts:

  1. In the main menu, go to Monitoring & reporting Alerts.
  2. Do one of the following:
    • Select the check boxes next to the alerts whose status you want to change.
    • Click the link with the ID of the alert whose status you want to change.

      The Alert details window opens.

  3. Click the Change status button.
  4. In the Change status pane, select the status to set.

    If you select the Closed status, you must select a resolution.

    If you change the alert status to Closed and this alert contains uncompleted playbooks or response actions, all related playbooks and response actions will be terminated.

  5. Click the Save button.

The status of the selected alerts is changed.

See also:

About alerts

Viewing the alert table

Assigning alerts to analysts

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.