Skip navigation
All Places > Products > RSA NetWitness Platform > RSA NetWitness Platform Online Documentation > Documents
Log in to create and rate content, and to follow, bookmark, and share content with other members.

Alerting: View a Summary of Alerts

Document created by RSA Information Design and Development Employee on Jan 30, 2020Last modified by RSA Information Design and Development Employee on Nov 11, 2020
Version 5Show Document
  • View in full screen mode

In the Repond view, you can browse through various alerts from multiple sources. You can filter the alerts list to show only alerts of interest, such as by Alert Name, alert source, and a specific time range.

  1. Go to Respond > Alerts.
    The Respond Alerts List view displays a list of all NetWitness Platform alerts.
    Respond Alerts List View

  2. In the Filters panel on the left, you can filter the alerts list to view specific alerts for a specific time frame. For example, in the Alert Names section, you can select an alert for an ESA rule, such as Direct Login to an Administrative Account, and leave the Time Frame set to Last Hour.
    The alerts list to the right shows a list of alerts that match your filter selection along with a count of the alerts at the bottom of the alerts list.
    Respond Alerts List Filtered
    The alerts list shows information about each of the alerts.
    • Created: Displays the date and time when the alert was created in the source system.
    • Severity: Displays the level of severity of the alert. The values are from 1 to 100.
    • Name: Displays a basic description of the alert.
    • Source: Displays the original source of the alert.
    • # of Events: Indicates the number of events contained within an alert.
    • Host Summary: Displays details of the host, like the host name from where the alert was triggered.
    • Incident ID: Shows the incident ID of the alert. If there is no incident ID, the alert does not belong to an incident.
  3. You can click an alert in the list to open an Overview panel on the right where you can view raw alert metadata.
    Respond Alerts View Showing Overview Panel

For more information about filtering alerts and viewing alert details, see the NetWitness Respond User Guide.

You are here
Table of Contents > View ESA Stats and Alerts > View a Summary of Alerts