Viewing alerts
Viewing general alert information
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace.
The section that opens displays a list of alerts.
For each alert, the table displays the following information:
Tip
You can change the info columns displayed in the table. To do this, click
in the row with the column headers, select the columns, and click Apply.-
: Alert criticality level:- : Remark
- : Low severity
- : Medium severity
- : High severity
-
Alert: Alert header.
-
Threat type: Threat associated with the alert.
-
Source: Module which sent the alert.
-
Status: Alert status.
-
Classification: Activity classification.
-
Assignee: User responsible for the alert.
-
Created by and Modified at: Date and time the alert was created and last modified.
-
Incident: Incident associated with the alert.
-
Searching alerts
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace for which you want find the alerts.
-
Click
Filters to expand the filter panel.For search and analysis, you can use:
-
Text search by alert headers and descriptions.
-
Visual grouping by alert type.
-
Sorting by date and criticality level.
-
Filters.
Tip
You can also update the displayed filters. To do this, click
in the filter row and select the filters.
-
Viewing detailed alert information
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace.
-
To view alert details, click the table row with its name. The detailed info window that opens includes the following tabs:
OverviewDetailsRecommendationsCommentsHistoryThe Overview tab contains:
- Basic information.
- List of facts.
- List of affected resources.
The Details tab displays information in JSON format, which may vary based on the threat type. For example, resource IDs and the number of detected events categorized by data type.
The Recommendations tab contains recommendations for mitigating the threat.
The Comments tab contains a discussion of the alert.
The History tab contains information about changes made to the alert.