The alerts table displays one row for each alert or alert group. When multiple alerts of the same type are reported for a host, they are grouped into the same row on the alerts table. For more information, see Understanding alert groups.
The table below lists and describes each column in the alerts table.
Column | Description | Default Column |
|---|---|---|
Acknowledged | Displays the acknowledgment status associated with each alert:
| Y |
Acknowledged By | Displays the username of the administrator, analyst, senior analyst, or investigator who acknowledge the alert. | N |
Acknowledged Date/Time | Displays the date and time when the alert was acknowledged. | N |
Alert Type | Displays the alert type. You can filter alerts for a particular type by selecting the type from the drop-down list. The type currently selected is shown in the column header.
| Y |
Assessment | Displays the assessment name for the alert as a link to more details on the Host Alert Details page. See Host Alert Details page for more information. You can filter alerts by assessment in the following ways:
| Y |
Comments | Displays any comments entered by the user. | N |
Disposition | Displays a subset of alerts.
| Y |
Enrichment | Displays metadata that describes the alert. | Y |
Events | Displays the number of events in the alert. Click the column header to sort alerts by event count in ascending or descending order. | Y |
File Full Path | Displays the file path of the latest event for the alert. File paths are always available for MAL alerts and EXD alerts, but not always available for IOC alerts. | Y |
First Event | The timestamp of the oldest alert in the alert group. You can select a relative time (Today, Yesterday, Last 7 Days, Last 30 Days, This Month, or Last Month. Choose Custom to open a calendar to enter a specific range. Click the column header to sort alerts by First Event timestamps in ascending or descending order. You can use First Event with Last Event to narrow your results. | Y |
Hash | Displays the hash associated with the alert.
NOTE—Not all alerts will have an associated hash. | Y |
Host | Displays the hostname, which is a link to the host's details page.
| Y |
Host IP | Displays the source or destination IP address associated with the alert.
| Y |
Last Event | The timestamp of the most recent alert in the alert group. Click on the column header to sort alerts by Last Event timestamps in ascending or descending order. | Y |
Options | To mark an alert as a false positive, select Mark False Positive. For more information, see Marking an alert as a false positive . ( | Y |
Options | To acknowledge an alert, select Acknowledge. See Acknowledging alerts for more information. | Y |
Protection and Remediation | Displays the action taken on the alert. You can filter alerts for a particular status by selecting the status from the drop-down list. The status currently selected is shown in the column header.
| Y |
Selected | Allows you to select all, clear all, or select specific alert rows to delete or acknowledge. You can use the column to perform a bulk deletion or acknowledgment of all alerts in the Alerts Table. | Y |