Investigate and understand the extent and severity of any alert to further decide response actions.
The All Alerts screen () displays all the standalone alerts triggered by detection models.
The following table outlines the actions available on the Alert
View screen.
|
Action
|
Description
|
||
|
Investigate an alert
|
Understand the extent and severity of any alert to further decide response actions
|
||
|
Open a new case
|
Locate a Workbench alert and click Open new case to create a new case to handle the alert.
|
||
|
View alert details
|
Click the ID of an alert to view the summary, highlights and observable graph of the alert.
|
||
|
Filter alert data
|
Use the search box and the dropdown lists to filter alert data.
|
||
|
Change the view
|
Select an option from the View menu:
|
||
|
Change the alert status
|
Select one or more alerts and click Change Status to update the progress of alerts or investigations.
|
||
|
Change alert findings
|
Select one or more alerts and click Change Findings to update the findings of the case.
|
||
|
Assign owner
|
Select one or more alerts and click Assign Owner to assign accounts within your organization to the alerts.
|
||
|
Move alerts across Workbench insights
|
Select one or more alerts and select any of the following options:
|
||
|
See Automated Response Playbooks
|
Click Automated Response Playbooks to display the Automated Response playbooks available in the Security Playbooks app
|
