Closing alerts

Prev Next

You can close alerts from the Alerts page or when viewing the details of an alert. When closing alerts, you can add notes that explain why the alert was closed.

Note

You can also close a case to close alerts. Closing a case closes all alerts that belong only to that case. Alerts that also belong to one or more other cases are not closed.

To close one or more alerts from the Alerts page:
  1. From the main menu, select Investigate > Alerts.

  2. To close a single alert, right-click on an alert in the table and select Close from the pop-up menu. Alternatively, you can click kebab_icon.png at the end of the row for the alert and select Close.

    To close multiple alerts at one time, select the alerts in the table and then select Close from the n Rows Selected drop-down menu.

  3. Optionally, specify a reason for closing the alert on the Close Alert dialog and then click Close.

To close an alert from the details page:
  1. From the main menu, select Investigate > Alerts.

  2. Click on an alert in the alerts list to display the alert details.

  3. Select Close from the menu in the upper right corner of the alert details page.

  4. Optionally, specify a reason for closing the alert on the Close Alert dialog and then click Close.