Alert Details (Side Panel)
Analyst10 min
What it's for
Manage status, owner, and resolution of an alert from the Alert Details panel.
Steps
- Open an alert with View Details.
- Review tabs `Formatted View` and `Raw JSON`.
- In Alert Management: change `Status` (`Open`, `Investigating`, `Resolved`, `False Positive`), `Owner`, `Resolved By`.
- Click Save Changes (shows Saving...).
Expected result
- Alert updated with new status and assignments.
Tips
- Other actions: Open Full View, Execute Query (opens Logs), Copy, Copy ID, Copy JSON, Export JSON, Delete Alert.