Searching for alerts related to an observable

You can search and view alerts related to monitored objects.

To find alerts related to a monitored object from the object information window:

  1. Select the Network traffic events section in the application web interface window.
  2. Go to the Observables tab.
  3. In the table, select the object for which you want to view information.

    This opens a window containing information about the object.

  4. In the Show related drop-down list, select the criterion by which you want to find alerts related to the object: file name, MD5 hash of the file, domain name, or IP address.

The table of alerts filtered by the selected criterion is displayed.

To find alerts related to monitored objects in the table of monitored objects:

  1. Select the Network traffic events section in the application web interface window.
  2. Go to the Observables tab.
  3. Select the check boxes next to the names of the monitored objects for which you want to find related objects.

    At least one check box must be selected.

  4. In the Show related drop-down list, select the criterion by which you want to find alerts related to the object: file name, MD5 hash of the file, domain name, or IP address.

The table of alerts filtered by the selected criterion is displayed.

Page top