Monitoring alerts
The Alerts page displays a list of all unresolved violation alerts in the system. At the top of the page are 3 charts that help identify the level of alert activity in the system:
- Violations — number of unresolved and resolved violations in the past month.
- Unresolved violations — by risk level
- Time to resolve violations (Past month)
On the main Alerts page is a list of unresolved alerts. You can access the list of resolved alerts and notifications from the left menu pane. If you do not see the left menu pane, swipe to the left browser edge to show the menu.
Filter alerts
On the Alerts page, you can filter the listed alerts by doing any of the following:
- Use the search bar to locate a specific alert or trigger.
- From the left menu pane, click one of the available options to filter the list by server group or trigger group.
- Server groups are configured on the Company settings page. For more information, see Company settings
- Trigger groups are configured on the Triggers page. For more information, see Trigger groups.
Sort alert details
On the Alerts page, you can sort the listed alerts doing any of the following:
- Click
on the far right to show or hide headings that are relevant to you. - Select
Toggle density to change the amount of spacing in each row.
- Click a heading to sort the list by that heading.
- Click and drag a heading to move the column left or right.
Export alerts list
On the Alerts page, you can export the list of displayed alerts.
- Click
on the top-right corner of the table to export a copy of the listed items in .CSV or JSON format.- In the following dialog, select the preferred export format from the drop down list.
- Enter the number of rows that you want to export.
- Select the headings that you want to include in the export.
- Click Export.
- In the following dialog, right-click the bar and save the linked target file as instructed.
- When the file finishes downloading, click OK to close the dialog.
Display alert summaries
On the Alerts page, hover over the alert command or link text in the table to see a summary of the server, session, user status, or number of violations associated with that alert.
- In the summary display, click any of the linked text to see more details.
- Click Run in Sources to see the command in context on the Sources page.
- Click Run in Insights to create a new report about the summarized item.
Display command in detail
On the Alerts page, click a row to expand and show the alert command in the terminal display.
- >_ command triggered a violation.
- Click [link] to see the command output or child commands.
A. Search
Use the search bar to find specific command text.
B. Display mode
Click
to display the commands in List mode.
Click
to display the commands in Hierarchy mode.
C. User only
Toggle this option to only show all commands or only commands executed by a user.
D. Details
Toggle this option to show or hide the Details pane.
When you select any command in the terminal, the Details pane displays the information about the source of the command and any affected files.
In the Details pane, hover or click any linked text to see more details.
E. Scrub data
Scrubbing data redacts the command or output for all users.
NOTE: When you scrub one command, all instances of the same command is scrubbed as well.
- Click
to manually scrub sensitive information.The
icon is displayed in the Details pane or in the top-right corner of the command output display.
- When the field becomes editable, press Backspace to scrub some or all of the displayed information.
- Click
to save your changes.
- In the confirmation dialog, click Scrub.
Resolve an alert
On the Alerts page, you can resolve any alert in the Unresolved list.
- At the right-end of the alert row, click Resolve.
- In the following dialog, enter any required notes related to the alert.
- If there are other violations associated with the alert, you can click to enable them all be resolved at the same time.
- Click Resolve.
Resolve multiple alerts
On the Alerts page, you can choose to resolve some or all alerts in the Unresolved list simultaneously.
- At the left-end of the alert rows, select the check box beside all the alerts you want to resolve. Or, check the box in the heading row to select all alerts.

- At the top of the list, click Resolve selected.
- In the following dialog, enter any notes related to the alert or investigation that may be required.
- Click Resolve.