Automatic Triage Settings page

Prev Next

Use the Automatic Triage Settings page to control the number of triage requests so that your agents are not overwhelmed. You can use the Triage Settings page to control the acquisition of triage packages based on alert types. The Automatic Triage Settings page contains tabs for Automatic Triages and Timestamp Settings. These configuration settings determine whether a triage should be triggered. If the configured rate limit for the triage has not been exceeded, then the triage is triggered for the alert.

You can also use the Timestamp Settings tab on the Automatic Triage Settings page to specify the period of time before and after the event timestamp during which data is collected.

Automatic Triage is supported on Windows, macOS, and Linux endpoints.

Automatic triage settings are enabled by default, which means that auto-triage is enabled for all supported alert types. Administrators can use the configuration settings to disable auto-triage completely or disable automatic triage for specific alert types.

The Triage Settings page supports both legacy alerts and new alerts, including the following alert types:

  • IOC

  • ExD

  • PRO (This alert type is only available if you are using the Process Tracker module in conjunction with the Enricher module, and you have configured these modules to generate PRO alerts.

Note

When automatic triage is turned off, you can still manually request triage collections.