The Alert List page displays all alerts received from integrated devices and those generated in the NDR. It serves as the starting point for investigating and classifying alerts. You can quickly triage, scope, and accurately analyze alerts using the alerts table.
Toggle the Visualization switch to hide or show the alert chart.
The top of the page contains a donut chart and a bar graph. All alerts are visually summarized in a donut chart and detailed by severity percentages: critical, high, medium, and low. A bar chart on the right visualizes the alert distribution over the specified timelines. The chart indicates a significant number of alerts, primarily denoted with different colors to denote the severity of the alert.
The Status filter allows you to refine the displayed alerts based on their current state. This helps analysts manage workloads efficiently—prioritizing new alerts, tracking ongoing investigations, and monitoring remediation progress. Use the filter to view alerts by status, such as "New" to identify recent activity or "Open" to focus on active investigations.
The Type filter allows you to narrow down alerts based on their classification or category. It helps analysts quickly focus on specific areas of concern or category of alerts. For example, by selecting "Suppressed," the analyst can review past suppressed alerts.
The bottom of the page consists of a table with a list of the alerts in NDR. You can view the summary of the alert, investigate the event timelines, and take the necessary action on the alert.
Note
Some columns only appear when specific views are selected.
Column | Description |
|---|---|
Severity | Indicates the severity level of the alert. The alert risk is denoted by an icon with a label and represented by color codes. |
Alert Created | The date and time in UTC when the alert was generated or detected by the appliance. |
Alert Name | Provides the specific name or type of the alert, giving a quick summary of what was detected. |
MITRE TTP | MITRE ATT&CK tactics, techniques, and procedures associated with a detected alert. It categorizes the detected alert activity according to the relevant MITRE ATT&CK framework. |
Source IP | The IP address of the source that initiated the activity triggering the alert. |
Target IP | The IP address of the asset that was the recipient or target of the activity that triggered the alert. |
Device Type | The device that generated or detected the alert. |
Workflow Executions | Indicates how many automated workflow actions or playbooks have been triggered. |
Status | The processing status of the alert.
|
Target Port | The port number on the destination (Target IP) of the network communication or activity related to the alert. |
To investigate an alert:
Click
and from INVESTIGATION, select Alerts.The Alert List page is displayed.
Note
You can also navigate to this page by clicking the alert of interest from the Top Alerts widget in the Detection dashboard.
Click the alert you want to investigate, click
and select an option.