Kaspersky Unified Monitoring and Analysis Platform

Working with alerts

In the Alerts section of the KUMA web interface, you can view and process the alerts registered by the program. Alerts can be filtered. When you click the alert name, a window with its details opens.

The displayed date and time format depend your machine's locale. In the English version, the first day of the week is Sunday.

Alert overflow

Each alert and its related events cannot exceed the size of 16 MB. When this limit is reached:

  • New events can no longer be linked to the alert.
  • The alert has an Overflowed tag displayed in the Detected column. The same tag is displayed in the Details on alert section of the alert details window.

Overflowed alerts should be processed as soon as possible.

In this Help topic

Filtering alerts

Alert window

Processing alerts

Drilldown analysis

Alert storage period

Alert segmentation rules