Skip to content

Alert

  • Centrally displays all alert records.
  • All fields in alerts are read-only by default and cannot be edited.
  • Analysts do not modify alert data; they only investigate and respond based on the alert data.

View

img.png

Supports multiple filtering and sorting functions.

Detail

img_1.png

Alert operation panel

Artifacts

img_2.png

Related Artifact records

Enrichments

img_3.png

Associated Enrichment records

Raw Log

img_4.png

The original log content of the alert, in JSON format.

Unmapped Data

img_5.png

Data from the original alert that has not been mapped. By default, AI does not analyze this data.