In this window you can take a closer look at a specific alert and all the data related to it.
To see alert details,
In the Alerts section of the KUMA web interface, click the alert whose information you want to view.
The alert window opens with the alert name displayed in the top left corner of the window.
The upper part of the alert details window contains a toolbar and shows the alert priority and the user name to which the alert is assigned. Here you can process the alert: change its priority, assign it to a user, and close and create an incident using it.
The Details on alert section of the alert window contains the following data:
The Related events section of the alert window contains the table of events related to the alert. If you click icon near the correlation rule, the base events from this correlation rule will be displayed. Events can be sorted by priority and time.
When an event is selected, the details area opens in the right part of the web interface window. This area contains information about the selected event. If a correlation event is selected, this area also contains the Detailed view button that opens the correlation event window.
The Find in events links below correlation events and the Find in events button to the right of the section header are used for drilldown analysis.
The Related endpoints section of the alert window contains the table of hosts related to the alert. This information comes from events that are related to the alert. You can search for endpoints by using the Search for IP addresses or FQDN field. Assets can be sorted using the Count and Endpoint columns.
If assets are related to the alert, they are displayed in this section. Clicking the name of the asset opens the Asset details window.
The Related users section of the alert window contains the table of users related to the alert. This information comes from events that are related to the alert. You can search for users using the Search for users field. Users can be sorted by the Count, User, User principal name and Email columns.
The Change log section of the alert window contains entries about changes made to the alert by users. Changes are automatically logged, but it is also possible to add comments manually. Comments can be sorted by using the Time column.
To add a comment to an alert,
In the alert window, enter the comment to the Comment field and click Add.
Page top