Alerts table

Prev Next

The alerts table displays one row for each alert or alert group. When multiple alerts of the same type are reported for a host, they are grouped into the same row on the alerts table. For more information, see Understanding alert groups.

The table below lists and describes each column in the alerts table.

Column

Description

Default Column

Acknowledged

Displays the acknowledgment status associated with each alert:

  • All (default)

  • Yes (acknowledged alerts)

  • No (unacknowledged alerts)

Y

Acknowledged By

Displays the username of the administrator, analyst, senior analyst, or investigator who acknowledge the alert.

N

Acknowledged Date/Time

Displays the date and time when the alert was acknowledged.

N

Alert Type

Displays the alert type. You can filter alerts for a particular type by selecting the type from the drop-down list. The type currently selected is shown in the column header.

  • ALL (default)

  • IOC—Indicators of Compromise

    • PRS—Presence

    • EXC—Execution

  • MAL—Malware

  • XPLT—Exploit

  • PRO—PROCESS_TRACKER

  • GEN—General

Y

Assessment

Displays the assessment name for the alert as a link to more details on the Host Alert Details page. See Host Alert Details page for more information.

You can filter alerts by assessment in the following ways:

  • Click inside the column header to filter alerts by a full or partial assessment name.

  • Click the column header to sort alerts by assessment name in ascending or descending order.

Y

Comments

Displays any comments entered by the user.

N

Disposition

Displays a subset of alerts.

  • All (default)

  • False Positive

  • Not False Positive

Y

Enrichment

Displays metadata that describes the alert.

Y

Events

Displays the number of events in the alert. Click the column header to sort alerts by event count in ascending or descending order.

Y

File Full Path

Displays the file path of the latest event for the alert.

File paths are always available for MAL alerts and EXD alerts, but not always available for IOC alerts.

Y

First Event

The timestamp of the oldest alert in the alert group. You can select a relative time (Today, Yesterday, Last 7 Days, Last 30 Days, This Month, or Last Month. Choose Custom to open a calendar to enter a specific range. Click the column header to sort alerts by First Event timestamps in ascending or descending order. You can use First Event with Last Event to narrow your results.

Y

Hash

Displays the hash associated with the alert.

  • Click inside the column header to filter alerts by a full or partial hash.

NOTE—Not all alerts will have an associated hash.

Y

Host

Displays the hostname, which is a link to the host's details page.

  • Click inside the column header to filter alerts by a full or partial hostname.

  • Click the column header to sort alerts by hostname in ascending or descending order.

Y

Host IP

Displays the source or destination IP address associated with the alert.

  • Click inside the column header to filter alerts by a full or partial IP address.

  • Click the column header to sort alerts by IP addresses in ascending or descending order.

Y

Last Event

The timestamp of the most recent alert in the alert group. Click on the column header to sort alerts by Last Event timestamps in ascending or descending order.

Y

Options

To mark an alert as a false positive, select Mark False Positive. For more information, see Marking an alert as a false positive . (

Y

Options

To acknowledge an alert, select Acknowledge. See Acknowledging alerts for more information.

Y

Protection and Remediation

Displays the action taken on the alert. You can filter alerts for a particular status by selecting the status from the drop-down list. The status currently selected is shown in the column header.

  • ALL (default)

  • BLOCK

  • PARTIAL BLOCK

  • QUARANTINED

  • CLEANED

Y

Selected

Allows you to select all, clear all, or select specific alert rows to delete or acknowledge. You can use the column to perform a bulk deletion or acknowledgment of all alerts in the Alerts Table.

Y