The Alerts Page

Introduction

Use the Alerts page to review security alerts detected by Field Effect, investigate alert details, filter results, and export alert data for further analysis.


Alerts represent individual security detections analyzed by Field Effect. While many alerts are informational, significant findings may be correlated into an ARO (Action, Recommendation, or Observation) that requires attention. The Alerts page allows administrators and technical users to examine the underlying activity that contributes to those findings.


This article covers the following topics: 


Who Should use This Page?

The Alerts page is intended for administrators, security teams, and other technical users who need detailed visibility into security activity across their organization.


Access the Alerts Page

After logging into the MDR SIEM, navigate to Security > Alerts in the sidebar. 



Navigate the Alerts Page

The Alerts page is located in the Security section of the sidebar.

The page consists of two primary areas:

  • List view, which displays alerts
  • Details view, which provides additional information about a selected alert


List View

Each row represents a single alert. The following columns are available by default:


ColumnDescription
Alerted (UTC)The date and time the alert was generated.
Host NameThe device associated with the alert. Selecting the host name opens the device's detailed view.
SensorThe network appliance that generated the alert.
CategoryThe source that generated the alert, such as an analyst or endpoint.
TypeThe alert classification.
Sub-TypeA more specific category for the alert.
ActionThe resulting action, such as Blocked or Observed.
SeverityThe alert severity level.
MITREA link to the associated MITRE ATT&CK technique, when available.



Customize Columns

You can customize the information displayed in the List view.

  1. Select Edit Columns.
  2. Select the columns you want displayed.
  3. Clear any columns you do not want displayed.
  4. Select Apply.



You can also:

  • Resize columns by dragging their edges.
  • Sort a column by selecting its header.


 


Details View

Select an alert from the list to view additional information in the Details pane.


The Details view may include:

  • Alert metadata
  • Associated artifacts
  • Technical information
  • Links to related investigations



Select Expand to open the Details view in a larger window. If the alert is associated with an ARO, select View ARO to open the related ARO for further investigation.



Alert Flows

Some Endpoint EDR alerts include an Alert Flow. This provides a timeline of the events that led to the endpoint agent's response, helping you understand the sequence of activity associated with the detection.



Search, Filter, and Sort Alerts

Use the search bar to locate specific alerts. Common searches include:

  • Alerts for a specific device
  • Alerts generated by analysts
  • High-severity alerts
  • Endpoint EDR alerts
  • Alerts generated within a specific time range


The search interface provides suggested columns, operators, and values to help build queries. You can also enter your own custom search criteria.


Sort Alerts

Select a column header to sort alerts in ascending or descending order. You can also use the Order By option when building search queries.


Filter Alerts

Use filtering operators such as:

  • Is Not to exclude specific values.
  • Is Null to display entries with no value in the selected column.
  • Supported Date Formats


When filtering by date or time, the following formats are supported:

  • 2022-11-22T16:35:42
  • 2022-11-22T16:35:42Z
  • 2022-11-22T16:35:42.000
  • 2022-11-22T16:35:42.000+0000



Recommended Investigation Workflow

When reviewing alerts:

  1. Search or filter for the alerts you want to investigate.
  2. Select an alert from the List view.
  3. Review the alert details and associated artifacts.
  4. Review the Alert Flow if one is available.
  5. Open the related ARO for additional context and remediation guidance.


Export Alert Data

You can export all alerts or only filtered results.

  1. Apply any desired filters.
  2. Select the Export .csv icon.
  3. Save or open the exported file.



Exporting alerts can be useful for:

  • Incident investigations
  • Compliance reporting
  • Security reviews
  • Offline analysis and reporting



Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article