Changing an alert status

March 20, 2024

ID 221565

Expand all | Collapse all

As a work item, an alert has a status that shows the current state of the alert in its life cycle.

You can change alert statuses for your own alerts or alerts of other analysts only if you have the access right to read and modify alerts and incidents.

An alert can have one of the following statuses:

  • New
  • In progress
  • Closed
  • In incident

To change the status of one or several alerts:

  1. In the main menu, go to MONITORING & REPORTING Alerts.
  2. If you have both Kaspersky EDR Optimum and Kaspersky EDR Expert integrated into Kaspersky Security Center Cloud Console, the Alerts section is divided into two tabs. Go to the Expert tab. Otherwise, skip this step.
  3. Select the check boxes next to the alerts whose status you want to change.
  4. Click the Change status button.
  5. In the Change status window, select the status to set.

    If you set the Closed status, you must select a resolution and provide a short comment.

  6. Provide a comment, if necessary.
  7. Click the Save button.

The status of the selected alerts is changed.

See also:

About alerts

Viewing the alert table

Assigning alerts to analysts

Did you find this article helpful?
What can we do better?
Thank you for your feedback! You're helping us improve.
Thank you for your feedback! You're helping us improve.