Investigating alerts

Prev Next

The Alert List page displays all alerts received from integrated devices and those generated in the NDR. It serves as the starting point for investigating and classifying alerts. You can quickly triage, scope, and accurately analyze alerts using the alerts table.

Toggle the Visualization switch to hide or show the alert chart.

The top of the page contains a donut chart and a bar graph. All alerts are visually summarized in a donut chart and detailed by severity percentages: critical, high, medium, and low. A bar chart on the right visualizes the alert distribution over the specified timelines. The chart indicates a significant number of alerts, primarily denoted with different colors to denote the severity of the alert.

The Status filter allows you to refine the displayed alerts based on their current state. This helps analysts manage workloads efficiently—prioritizing new alerts, tracking ongoing investigations, and monitoring remediation progress. Use the filter to view alerts by status, such as "New" to identify recent activity or "Open" to focus on active investigations.

The Type filter allows you to narrow down alerts based on their classification or category. It helps analysts quickly focus on specific areas of concern or category of alerts. For example, by selecting "Suppressed," the analyst can review past suppressed alerts.

The bottom of the page consists of a table with a list of the alerts in NDR. You can view the summary of the alert, investigate the event timelines, and take the necessary action on the alert.

Note

Some columns only appear when specific views are selected.

Column

Description

Severity

Indicates the severity level of the alert. The alert risk is denoted by an icon with a label and represented by color codes.

Alert Created

The date and time in UTC when the alert was generated or detected by the appliance.

Alert Name

Provides the specific name or type of the alert, giving a quick summary of what was detected.

MITRE TTP

MITRE ATT&CK tactics, techniques, and procedures associated with a detected alert. It categorizes the detected alert activity according to the relevant MITRE ATT&CK framework.

Source IP

The IP address of the source that initiated the activity triggering the alert.

Target IP

The IP address of the asset that was the recipient or target of the activity that triggered the alert.

Device Type

The device that generated or detected the alert.

Workflow Executions

Indicates how many automated workflow actions or playbooks have been triggered.

Status

The processing status of the alert.

  • New: The alert is new.

  • Open: The alert is in open state

  • Closed: The alert is in closed state

Target Port

The port number on the destination (Target IP) of the network communication or activity related to the alert.

To investigate an alert:

  1. Click Main_menu.png and from INVESTIGATION, select Alerts.

    The Alert List page is displayed.

    Note

    You can also navigate to this page by clicking the alert of interest from the Top Alerts widget in the Detection dashboard.

  2. Click the alert you want to investigate, click Browse.JPG and select an option.