Alert Configurations
An alert configuration is a rule that watches your endpoints and raises an alert when its conditions are met. It can also trigger actions (like an integration) and attach remediations.
How to get here
You reach this page through Settings, so you need administrator (settings) permission. If you don't see the Settings icon, ask your administrator for access.
- Sign in to EndpointOps.
- In the top-right of any screen, click the Settings (gear ⚙️) icon.
- In the Settings menu on the left, open Policy Management and click Alert Configurations.
Navigate to: Settings → Policy Management → Alert Configurations
URL path: /settings/policy-management/policies
The Alert Configurations screen

Columns: Name, Severity, Scope, Module, Status, Description, Created At. The Status column is a switch you can flip in the list. Each row has edit (✏️) and delete (🗑️) actions.
The toolbar
Above the list, the same toolbar appears on every list screen:
- Create- add a new item (opens a form panel from the right).
- Refresh- reload the latest data.
- Export- download the current list.
- Columns- choose which columns to show (covered under "Choosing which columns to show" below).
Working with the list
These controls behave the same on every list:
- Search- type in the Search… box above the table to filter rows as you type.
- Sort- click the arrows in a column header to sort by that column.
- View details- click a row's link in the first column to open a read-only view.
- Edit / delete- use the edit (✏️) and delete (🗑️) icons at the end of a row.
- Pagination- when a list runs to more than one page, use the page controls at the bottom-right and the / page selector to change how many rows show.
- Permissions- you only see Create, edit, and delete if your role grants the matching permission; otherwise the screen is read-only.
When you save a new or edited record, a success message appears, the panel closes, and the list refreshes. Required fields are marked with a red asterisk.
How do I create an alert configuration?
-
Click Create. The Create Alert Configuration panel opens.

-
Fill in the fields (red asterisk = required):
Field Required Notes Name Yes A label for the rule. Description Yes What it watches for. Status - Enable or disable the rule (on by default). Module - What it applies to (for example Endpoint). Severity Yes The alert severity to raise. Scope Yes Which endpoints it applies to- pick a filter and, optionally, specific endpoints. Conditions Yes One or more Attribute → Condition → Value rules. Add more and join them with AND / OR. Add Actions - Integrations to run when the alert fires (from Market Place). Add Remediations - Remediations to attach. -
Click Create.
Choosing which columns to show
Click the Columns icon on the right of the toolbar to open the column picker.

Tick the columns to show, untick to hide, drag to reorder, then click Apply.
Related
- Endpoint Vital- custom command-based checks.
- Market Place- integrations used as alert actions.
- Audit- a log of changes, including to these rules.