In the Alert Details view (RESPOND >Alerts > click a NAME hyperlink in the Alerts List), you can view summary information about an alert, such as the source of the alert, the number of events within the alert, and whether it is part of an incident. You can also view detailed information about the events within the alert as well as the event metadata.
This workflow shows the high-level process that Analysts use to review alerts and create incidents.
After reviewing the alerts list, in the Alert Details view, you can investigate those alerts further and create incidents from the alerts. In the CONFIGURE > INCIDENT RULES view, you can create aggregation rules to create incidents.
What do you want to do?
*You can complete these tasks here (that is in the Alerts Details view).
Alert Details View
To access the Alert Details view, go to RESPOND > Alerts.
- In the Alerts list, choose an alert to view and then click the link in the NAME column for that alert.
The Alert Details view has an Overview panel on the left and the Events panel on the right. You can resize the panels to show more information as shown in the following figure.
The Overview panel shows basic summary information about a selected alert. The Overview panel on the Alerts List view contains the same information. The Alerts List view Overview Panel topic provides details.
The Events panel can show an Events List if there is more than one event in the alert. If there is only one event in the alert, or you click an event in the Events List, you can see Event Details in the Events panel.
The Events List for a selected alert shows all of the events contained in that alert.
The following table lists some of the columns shown in the Events List, which provide a summary of the listed events.
The Event Details in the Events panel shows the event metadata for each event in the alert.
The following table lists some event metadata sections and subsections shown in the first two columns in the Event Details. This is not an extensive list.
The following table lists attributes for an event source or destination device that can be shown in the Events Details.
The following table lists attributes for an an event source or destination user that can be shown in the Events Details.
This table lists the toolbar actions available in the Alert Details view.