Introduction
Use the Alerts page to review security alerts detected by Field Effect, investigate alert details, filter results, and export alert data for further analysis.
Alerts represent individual security detections analyzed by Field Effect. While many alerts are informational, significant findings may be correlated into an ARO (Action, Recommendation, or Observation) that requires attention. The Alerts page allows administrators and technical users to examine the underlying activity that contributes to those findings.
This article covers the following topics:
- Who should use this page?
- Access the Alerts Page
- Navigate the Alerts Page
- Search, Filter, and Sort Alerts
- Recommended Investigation Workflow
- Export Alert Data
Who Should use This Page?
The Alerts page is intended for administrators, security teams, and other technical users who need detailed visibility into security activity across their organization.
Access the Alerts Page
After logging into the MDR SIEM, navigate to Security > Alerts in the sidebar.

Navigate the Alerts Page
The Alerts page is located in the Security section of the sidebar.
The page consists of two primary areas:
- List view, which displays alerts
- Details view, which provides additional information about a selected alert
List View
Each row represents a single alert. The following columns are available by default:
| Column | Description |
|---|---|
| Alerted (UTC) | The date and time the alert was generated. |
| Host Name | The device associated with the alert. Selecting the host name opens the device's detailed view. |
| Sensor | The network appliance that generated the alert. |
| Category | The source that generated the alert, such as an analyst or endpoint. |
| Type | The alert classification. |
| Sub-Type | A more specific category for the alert. |
| Action | The resulting action, such as Blocked or Observed. |
| Severity | The alert severity level. |
| MITRE | A link to the associated MITRE ATT&CK technique, when available. |

Customize Columns
You can customize the information displayed in the List view.
- Select Edit Columns.
- Select the columns you want displayed.
- Clear any columns you do not want displayed.
- Select Apply.

You can also:
- Resize columns by dragging their edges.
- Sort a column by selecting its header.
Details View
Select an alert from the list to view additional information in the Details pane.
The Details view may include:
- Alert metadata
- Associated artifacts
- Technical information
- Links to related investigations

Select Expand to open the Details view in a larger window. If the alert is associated with an ARO, select View ARO to open the related ARO for further investigation.

Alert Flows
Some Endpoint EDR alerts include an Alert Flow. This provides a timeline of the events that led to the endpoint agent's response, helping you understand the sequence of activity associated with the detection.

Search, Filter, and Sort Alerts
Use the search bar to locate specific alerts. Common searches include:
- Alerts for a specific device
- Alerts generated by analysts
- High-severity alerts
- Endpoint EDR alerts
- Alerts generated within a specific time range
The search interface provides suggested columns, operators, and values to help build queries. You can also enter your own custom search criteria.
Sort Alerts
Select a column header to sort alerts in ascending or descending order. You can also use the Order By option when building search queries.
Filter Alerts
Use filtering operators such as:
- Is Not to exclude specific values.
- Is Null to display entries with no value in the selected column.
- Supported Date Formats
When filtering by date or time, the following formats are supported:
- 2022-11-22T16:35:42
- 2022-11-22T16:35:42Z
- 2022-11-22T16:35:42.000
- 2022-11-22T16:35:42.000+0000

Recommended Investigation Workflow
When reviewing alerts:
- Search or filter for the alerts you want to investigate.
- Select an alert from the List view.
- Review the alert details and associated artifacts.
- Review the Alert Flow if one is available.
- Open the related ARO for additional context and remediation guidance.
Export Alert Data
You can export all alerts or only filtered results.
- Apply any desired filters.
- Select the Export .csv icon.
- Save or open the exported file.

Exporting alerts can be useful for:
- Incident investigations
- Compliance reporting
- Security reviews
- Offline analysis and reporting

Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article