Viewing alerts
Viewing general alert information
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace.
The section that opens displays a list of alerts.
For each alert, the table displays the following information:
-
: Alert criticality level:- : Remark
- : Low severity
- : Medium severity
- : High severity
-
Alert: Alert header.
-
Threat type: Threat associated with the alert.
-
Source: Module which sent the alert.
-
Status: Alert status.
-
Classification: Activity classification.
-
Assignee: User responsible for the alert.
-
Created at and Modified at: Date and time the alert was created and last modified.
-
Incident: Incident associated with the alert.
-
-
Optionally, configure alert display.
Searching alerts
- Go to Yandex Security Deck
. - In the left-hand panel, select
Alerts. - At the top of the window, select the workspace for which you want find the alerts.
- In the search bar, enter a part of the header or description of the alert you want to find.
- Optionally, configure how to display search results.
Customizing alert display
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace you want to view alerts for.
-
Group alerts by issue or alert type. To the right of the search bar, click
and select a grouping type. -
Sort alerts by date or severity level. Above the filter panel, click
and select a sorting type. -
To filter alerts, use the panel above the table. In drop-down lists, select the required values.
To configure filter visibility, click
to the right of the filter and select the values to show or hide. -
Configure column visibility. Click
on the right side of the table header. Select the values you need and click Apply.
Viewing detailed alert information
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace.
-
To view alert details, click the table row with its name. The detailed info window that opens includes the following tabs:
OverviewDetailsRecommendationsCommentsHistoryThe Overview tab contains:
- Basic information.
- List of facts.
- List of affected resources.
The Details tab displays information in JSON format, which may vary based on the threat type. For example, resource IDs and the number of detected events categorized by data type.
The Recommendations tab contains recommendations for mitigating the threat.
The Comments tab contains a discussion of the alert.
The History tab contains information about changes made to the alert.
Tip
You can create an exception on the KSPM and CSPM alerts page.