Viewing the alerts list

Prev Next

The Alerts page shows summary information about the alerts in your environment, as well as a table of alerts. It is your starting point for investigating, classifying, assigning, and escalating alerts.

Note

The federated view of the Alerts page centralizes alerts across multiple organizations managed by a managed security service provider (MSSP) into a single federated view. This view is displayed instead of the Alerts page for credentialed users who are logged into the MSSP Helix Enterprise instance. For details, see Using the alert list in federated view.

To access the Alerts page, from the main menu select Investigate > Alerts.

The Alerts page has two main sections: a general information section and an alerts table.

General alert information

The top of the page contains summary information, including statistics about the number of alerts over the last 30 days. A chart provides a visual display, by date and risk level, that helps you determine patterns.

Alerts table

The table in the lower half of the page contains a list of the alerts created in Helix Enterprise. You can select one of two views of the alerts table:

  • Basic Alerts View (the default)

  • Extended Alerts View

Select the view you want using the drop-down menu on the tab.

You can filter or otherwise customize the alerts table using the buttons to the left of the alerts table.

You can perform bulk actions on alerts to assess and set status on multiple alerts at one time instead of performing the same action multiple times on individual alerts.

For more information, see Customizing the alerts table. Click Reset All Filters to reset any filters you set.

The Alerts table contains the following columns. As noted, some columns only appear when specific views are selected.

Note

For the additional column and options available in the federated view, see Using the alert list in federated view.

Column

Description

Risk

The alert risk is denoted by a label and represented by a series of colored dots.

  • Four red dots indicate that the alert is a critical alert.

  • Three orange dots indicate that the alert is an alert with high risk.

  • Two yellow dots indicate that the alert is an alert with medium risk.

  • One blue dot indicates that the alert is an alert with low risk.

You can sort the results in ascending and descending order and select the results from the drop-down list options (Critical, High, Medium, and Low). More than one risk can be selected.

Name

The official name and ID of the alert.

You can filter the alerts table by alert name but not by alert ID. Enter all or part of an alert name in the Name column heading.

The activity that triggered the alert is displayed when you hover over the link in this column. If the alert has events with MITRE IDs, the MITRE technique and ID are displayed.

Organization

The organization associated with the alert.

You can click the column header to filter by organization. By default, alerts for all organizations are displayed.

Type

The type of alert.

You can filter the alerts table by alert type. Enter all or part of an alert type in the Type column heading.

Origin

The origin of the alert.

  • Trellix Rule: The alert was triggered by a Trellix rule.

  • Trellix Rule (Tuned): The alert was triggered by a Trellix rule that was tuned for your environment.

  • Customer Rule: The alert was triggered by a rule you created.

  • Trellix Intel: The alert was triggered by Trellix Intel.

  • Trellix Analytics: The alert was triggered by Trellix Analytics.

  • Trellix Sinkhole: The alert was triggered by Trellix Sinkhole.

You can filter the alerts table by alert origin. Select an alert origin in the drop-down list in the Origin column heading. Select All Origins to see alerts from all origins.

First Event

The timestamp of the first event that triggered the alert.

You can sort the results in this column in ascending and descending order based on the first event.

Last Event

The timestamp of the last event that triggered the alert.

You can sort the results in the Last Event column in ascending and descending order based on the last event.

Events

The number of events that have triggered the alert.

You can sort the alerts table by this count. Click the Events column heading to sort it. Repeatedly clicking the heading flips the sort back and forth between an ascending sort and a descending sort.

Intel Source

The source of any intelligence available about the alert. The options are Insights or Mandiant. If no intelligence is available, the field is empty.

You can filter the alerts table by intelligence source. Select a source in the drop-down list in the Intel Source column heading. You can sort the alerts table by intelligence source. Click the Intel Source column heading to sort it.

Summary

A brief summary of the alert.

You can filter the alerts table by the alert summary. Enter all or part of an alert summary in the Summary column heading.

Source/Destination

The source and destination of the alert. The source is shown above the destination. You can search data based on text entered in this column heading.

State

The state of the alert.

  • Open: The alert is in an open state.

  • Suppressed: The alert is in a suppressed state.

  • Closed: The alert is in a closed state.

  • Reopened: The alert is in a reopened state.

You can filter the alerts table by alert state. Select an alert state in the drop-down list in the State column heading. Select All States to see alerts in any state.

Created At

(Extended Alerts View only)

The date and time in UTC the alert was created.

Hash

(Extended Alerts View only)

The hash of the alert.

You can filter the alerts table by the alert hash. Enter all or part of an alert hash in the Hash column heading.

Assignee

(Extended Alerts View only)

The person assigned to review the alert.

You can filter the alerts table by the assignee. Enter all or part of an alert hash in the Assignee column heading or select an assignee from the drop-down list in the Assignee column heading. Select All users to see alerts for all assignees.

Queues

(Extended Alerts View only)

The alert queue to which the alert is assigned.

You can filter the alerts table by alert queue. Select an alert queue in the drop-down list in the Queues column heading. Select All Queues to see alerts in all queues.

Assessment (Extended Alerts View only)

The assessment of the alert.

You can filter the alerts table by assessment value. Select an assessment value in the drop-down list in the Assessment column heading. Select All Assessments to see alerts with any assessment value.

Alerts are assessed when you review the alert on its alert details page. See Assessing an alert.

(Actions)

Click kebab_icon.png at the end of the row to perform one of the following actions on an alert:

To perform bulk actions on alerts, select the alerts in the left-most column, and select the action from the button at the top right of the table.