Skip to content

Alerts and findings

A finding is one detection on one device. Findings for the same person, device and rule within the grouping window (30 minutes by default, configurable in Settings → Alerting & devices) form an alert. The alert's severity is the highest severity of its findings.

Alerts

Triage

Alerts has tabs by status, filters (severity, rule, group, person, device, assignee, time range) and search by rule, person, device or alert number (for example ALR-1042). Select several alerts to change their status in bulk.

StatusUse it when
OpenNew, nobody has looked at it yet
AcknowledgedSomeone is working on it; assign it to make ownership clear
ResolvedHandled, for example the key was rotated or the data deleted
False positiveNot sensitive after all; a note is required so rules can be tuned

Alert detail

Alert detail

The alert page shows:

  • the findings timeline with masked matches, the source application, content type and length, and the actions taken on the device (clipboard cleared, user notified, excluded from sync);
  • status, assignee and comments for coordination;
  • evidence requests for the alert's findings;
  • history: every change to the alert from the audit log.

Findings

Findings lists every finding with the same filters. Use it to hunt across alerts, for example all findings from one source application this week, or every finding with sealed evidence still available on the device.

TIP

Send alert.created for high and critical alerts to your SIEM or on-call channel with an integration, and triage everything else in the console.

Klipsu Sentinel is a product of Lygon Software · enterprise@klipsu.com