The Alerts page shows summary information about the alerts in your environment, as well as a table of alerts. It is your starting point for investigating, classifying, assigning, and escalating alerts.
Note
The federated view of the Alerts page centralizes alerts across multiple organizations managed by a managed security service provider (MSSP) into a single federated view. This view is displayed instead of the Alerts page for credentialed users who are logged into the MSSP Helix Enterprise instance. For details, see Using the alert list in federated view.
To access the Alerts page, from the main menu select Investigate > Alerts.
The Alerts page has two main sections: a general information section and an alerts table.
General alert information
The top of the page contains summary information, including statistics about the number of alerts over the last 30 days. A chart provides a visual display, by date and risk level, that helps you determine patterns.
Alerts table
The table in the lower half of the page contains a list of the alerts created in Helix Enterprise. You can select one of two views of the alerts table:
Basic Alerts View (the default)
Extended Alerts View
Select the view you want using the drop-down menu on the tab.
You can filter or otherwise customize the alerts table using the buttons to the left of the alerts table.
You can perform bulk actions on alerts to assess and set status on multiple alerts at one time instead of performing the same action multiple times on individual alerts.
For more information, see Customizing the alerts table. Click Reset All Filters to reset any filters you set.
The Alerts table contains the following columns. As noted, some columns only appear when specific views are selected.
Note
For the additional column and options available in the federated view, see Using the alert list in federated view.
Column | Description |
|---|---|
Risk | The alert risk is denoted by a label and represented by a series of colored dots.
You can sort the results in ascending and descending order and select the results from the drop-down list options (Critical, High, Medium, and Low). More than one risk can be selected. |
Name | The official name and ID of the alert. You can filter the alerts table by alert name but not by alert ID. Enter all or part of an alert name in the Name column heading. The activity that triggered the alert is displayed when you hover over the link in this column. If the alert has events with MITRE IDs, the MITRE technique and ID are displayed. |
Organization | The organization associated with the alert. You can click the column header to filter by organization. By default, alerts for all organizations are displayed. |
Type | The type of alert. You can filter the alerts table by alert type. Enter all or part of an alert type in the Type column heading. |
Origin | The origin of the alert.
You can filter the alerts table by alert origin. Select an alert origin in the drop-down list in the Origin column heading. Select All Origins to see alerts from all origins. |
First Event | The timestamp of the first event that triggered the alert. You can sort the results in this column in ascending and descending order based on the first event. |
Last Event | The timestamp of the last event that triggered the alert. You can sort the results in the Last Event column in ascending and descending order based on the last event. |
Events | The number of events that have triggered the alert. You can sort the alerts table by this count. Click the Events column heading to sort it. Repeatedly clicking the heading flips the sort back and forth between an ascending sort and a descending sort. |
Intel Source | The source of any intelligence available about the alert. The options are Insights or Mandiant. If no intelligence is available, the field is empty. You can filter the alerts table by intelligence source. Select a source in the drop-down list in the Intel Source column heading. You can sort the alerts table by intelligence source. Click the Intel Source column heading to sort it. |
Summary | A brief summary of the alert. You can filter the alerts table by the alert summary. Enter all or part of an alert summary in the Summary column heading. |
Source/Destination | The source and destination of the alert. The source is shown above the destination. You can search data based on text entered in this column heading. |
State | The state of the alert.
You can filter the alerts table by alert state. Select an alert state in the drop-down list in the State column heading. Select All States to see alerts in any state. |
Created At (Extended Alerts View only) | The date and time in UTC the alert was created. |
Hash (Extended Alerts View only) | The hash of the alert. You can filter the alerts table by the alert hash. Enter all or part of an alert hash in the Hash column heading. |
Assignee (Extended Alerts View only) | The person assigned to review the alert. You can filter the alerts table by the assignee. Enter all or part of an alert hash in the Assignee column heading or select an assignee from the drop-down list in the Assignee column heading. Select All users to see alerts for all assignees. |
Queues (Extended Alerts View only) | The alert queue to which the alert is assigned. You can filter the alerts table by alert queue. Select an alert queue in the drop-down list in the Queues column heading. Select All Queues to see alerts in all queues. |
Assessment (Extended Alerts View only) | The assessment of the alert. You can filter the alerts table by assessment value. Select an assessment value in the drop-down list in the Assessment column heading. Select All Assessments to see alerts with any assessment value. Alerts are assessed when you review the alert on its alert details page. See Assessing an alert. |
(Actions) | Click
To perform bulk actions on alerts, select the alerts in the left-most column, and select the action from the button at the top right of the table. |
