Viewing alerts
Viewing general alert information
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace.
The section that opens displays a list of alerts.
For each alert, the table displays the following information:
Tip
If you need to, you can change the info columns displayed in the table. Do it by clicking
in the row with the table column headers, selecting the info columns you need, and clicking Apply.-
: Alert criticality level:- : Remark
- : Low severity
- : Medium severity
- : High severity
-
Alert: Alert header.
-
Threat type: Threat associated with the alert.
-
Source: Module which sent the alert.
-
Status: Alert status.
-
Classification: Activity classification.
-
Assignee: User responsible for the alert.
-
Created by and Modified at: Date and time the alert was created and last modified.
-
Incident: Incident associated with the alert.
-
Searching alerts
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace for which you want find the alerts.
-
Click
Filters to expand the filter panel.For search and analysis, you can use:
- Text search by alert headers and descriptions.
- Visual grouping by alert type.
- Sorting by date and criticality level.
- Filters.
Viewing detailed alert information
-
Go to Yandex Security Deck
. -
In the left-hand panel, select
Alerts. -
At the top of the window, select the workspace.
-
To view alert details, click the table row with its name. The detailed info window that opens includes the following tabs:
OverviewDetailsRecommendationsCommentsHistoryThe Overview tab contains:
- Basic information.
- List of facts.
- List of affected resources.
The Details tab displays information in JSON format, which may vary based on the threat type. For example, resource IDs and the number of detected events categorized by data type.
The Recommendations tab contains recommendations for mitigating the threat.
The Comments tab contains a discussion of the alert.
The History tab contains information about changes made to the alert.
Tip
You can create an exception on the KSPM and CSPM alerts page.