Viewing correlated SmartVision and network alerts using the Web UI

Prev Next

If a SmartVision alert that involves a file transfer also triggers an network alert (an alert listed in the Alerts > Alerts > Alerts tab), the correlation is flagged in both alert lists:

In the SmartVision alerts list

A “Network Correlated” badge identifies a SmartVision alert correlated with a network alert.

To view the MVX analysis for a network-correlated SmartVision alert:
  1. Select Alerts > SmartVision.

  2. In the SmartVision Alerts list, identify the network-correlated alert you want to investigate. This type of SmartVision alert is flagged by a “Network Correlated” badge:

    badge_NetworkCorrelated.png
  3. To view the file’s MVX analysis results (malicious or benign), click “Associated File Analysis” in the Artifacts column:

    badge_SmartVisionCorrelated_results.png

    MVX analysis results are provided for each file involved in the SmartVision alert.

In the network alerts list

A “ SmartVision Correlated” badge identifies a network alert correlated with a SmartVision alert.

To view the SmartVision event that also triggered a network alert:
  1. Select Alerts > Alerts > Alerts.

  2. In the network alerts list, select the -correlated alert you want to investigate. This type of network alert is flagged by a “ SmartVision Correlated” badge in the Badges column:

    badge_SmartVisionCorrelated.png
  3. To view the associated event, click the “ SmartVision Correlated” badge.