The Alerts List view (RESPOND > Alerts) enables you to view all of the threat alerts and indicators received by NetWitness Suite in one location. This can include alerts received from ESA Correlation Rules, ESA Analytics, Malware Analysis, Reporting Engine, NetWitness Endpoint, as well as many others. In the Alerts List view you can browse through various alerts, filter them, and group them to create incidents.
This workflow shows the high-level process that Analysts use to review alerts and create incidents.
In the Alerts List view, you can review a list of alerts from all sources received by NetWitness Suite. After that, you can investigate those alerts further and create incidents from the alerts or you can create aggregation rules to create incidents.
What do you want to do?
*You can complete these tasks here (that is in the Alerts List view).
Alerts List View
To access the Alerts List view, go to RESPOND > Alerts. The Alerts List view displays a list of all alerts and indicators received by the Respond Server database in NetWitness Suite. The following figure shows the Filters panel on the left.
The Alerts List view consists of a Filters panel, an Alerts List, and an Alert Overview panel. You can click an alert in the Alerts list to view the Alert Overview panel on the right.
The Alerts List shows all of the alerts in NetWitness Suite. You can filter this list to only show alerts of interest.
At the bottom of the list, you can see the number of alerts on the current page, the total number of alerts, and the number of alerts selected. For example: Showing 377 out of 377 items | 3 selected
The following figure shows the filters available in the Filters panel.
The Filters panel, on the left of the Alerts List view, has options that you can use to filter the alerts list. When you navigate away from the Filters panel, the Alerts List view retains your filter selections.
The Alerts List shows a list of alerts that meet your selection criteria. You can see the number of items in your filtered list at the bottom of the alerts list. For example: Showing 30 out of 30 items
The Overview panel shows basic summary information about a selected alert and raw alert metadata. The Overview panel in the Alert Details view contains the same information, but in the Alerts Details view, you can expand the panel to view more information.
The following table lists the fields displayed in the Alert Overview panel.
This table lists the toolbar actions available in the Alerts List view.