Skip to main content

Alert

The Alert tab shows the security and policy alerts raised for this one endpoint- the per-machine slice of the fleet-wide Alerts screen.

How to get here

Open an endpoint (see Summary), then click the Alert tab.

URL path: /inventory/endpoints/{id}?tab=alert

The Alert tab

The Alert tab for one endpoint, with module and severity filtersThe Alert tab for one endpoint, with module and severity filters

Filters on the left narrow the list by Modules and Severity, each with counts.

ColumnWhat it shows
(icon)Threat-context indicator for alerts that matched a threat feed.
AlertWhat was detected.
SeverityA colour-coded tag.
ModuleThe feature that raised it.
AttributeThe item the rule looked at.
ValueThe value that triggered it.
MessageA fuller description.
Created OnWhen it was raised.

Above the table: a timeline picker to scope the range, Configure Alert (jumps to the alert policy settings), and a list / card view toggle.

Tips & troubleshooting

  • No alerts. Nothing has triggered for this endpoint in the selected timeline- widen the range or set Severity to All.
  • An alert keeps recurring. It will until the condition is fixed on the machine, or the rule is changed under Alert Configurations.
  • Alerts- the same alerts across your whole fleet.
  • Process- a flagged process is a common alert source.