Working with alerts

This section contains general information about alerts, their properties, typical life cycle, and connection with incidents. The instructions that are provided will help you analyze the alert table, change alert properties according to the current state in the life cycle, and combine alerts into incidents by linking or unlinking the alerts.

The Alerts section is displayed in the main menu if the following conditions are met:

In this section

About alerts

Alert data model

Viewing the alert table

Viewing alert details

Assigning alerts to analysts

Changing an alert status

Creating alerts manually

Linking alerts to incidents

Unlinking alerts from incidents

Linking events to alerts

Unlinking events from alerts

Working with alerts on the investigation graph

Managing aggregation rules

Page top