Several different alert counts appear on host pages in the Endpoint Security (HX) Web UI.
The Alerts page and the Hosts with Alerts tab show the number of alerts generated when agents found matching activity on their host endpoints. More than one alert can be generated for each condition.
The alert list in the host alert details section of the Host Alert Details page shows the alerts generated when EDRF Client found matching activity for the host endpoint. When you click on an alert, the condition that triggered the alert and the events that matched the condition are shown.
The condition description listed in the Alerted nnn times on box on the Host Alert Details page shows the number of alerts generated by the condition on the host. This is the number of instances of the alert generated for the host.
For example, if an EDRF Client reports endpoint beaconing to a known malicious command and control (CnC) server, the Endpoint Security (HX) groups all further reports of beaconing activity to that server as one condition. The Endpoint Security (HX) does not display a separate alert each time the agent reports activity matching a condition. The actual number of instances for a condition is reported at the top of the alert details section of the page as Alerted nnn times on.
Note
If you view Endpoint Security (HX) alerts in a SIEM console, you might see each instance of activity as a separate alert.