Review alerts - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR Pro Administrator Guide

Product
Cortex XDR
License
Pro
Creation date
2024-07-16
Last date published
2024-12-04
Category
Administrator Guide
Retire_Doc
Retiring
Link_to_new_Doc
/r/Cortex-XDR/Cortex-XDR-Documentation
Abstract

The alerts table displays all the collections within the investigation that has identified suspicious or malicious activity within the forensics data sets.

The alerts table displays all the collections within the investigation that has identified suspicious or malicious activity within the forensics data sets.

Refer to Featured fields in Overview of the Alerts page for the descriptions of the table fields.Overview of the Alerts page

The following actions are available for a selected alert.

  • Change status

  • Change severity

  • Investigate causality chain

  • Run playbook

  • Manage alerts