Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

To access the Alerts overview area and change the alert status, you need at least the Triggered alerts (view) and the Read/unread alert permissions (see a detailed description of the alerts permissions here).

Additionally, you need to have alerts assigned with Manage access (see Assign resources to a role), which will be those you will see on the list.

...

  • Unread (0): the alert details have not been viewed yet by any user in the domain.

  • Watched (100): the alert's details have been viewed by any user in the domain.

  • False positive (2): the alert has been reviewed and deemed irrelevant for the purpose of the analysis.

  • Closed (300): the alert does not need to be monitored anymore. You can indicate in your user preferences if you want closed alerts to appear in the Alerts overview

  • Suppressed (800): the alert has been deemed unnecessary for further action (most of the time via post-filter). Suppression can be useful to reduce the noise in cases where recurring alerts are acknowledged but do not require immediate attention. Suppressed alerts are not actively monitored, but they remain in the system for auditing purposes and can be reinstated or reviewed if needed.

Changing status from the alert list

...