Triggered alert grouping
Triggered alerts from the same alert rule that haven't been investigated yet are grouped together. This lets users review and remediate them as a set instead of one at a time. The triggered alert grouping works as follows:
-
When a group has not yet been remediated, every new triggered alert from that alert rule joins the group. You can open the group to review information, such as when each alert was triggered, sample events, and the specific non-compliant values highlighted for each field.
-
When you start remediation from a group, all X triggered alerts in that group move to a "Remediation in progress" status. Any new triggered alerts from that alert rule after this point start a new group.
-
Once the AI finishes the analysis and remediation, the group's status changes to Done.
-
The triggered alerts in a Done group are not removed immediately. They remain visible until the alert rule's expiry setting is reached, at which point they disappear.
-
The expiry setting configured on the alert rule determines how long triggered alerts remain visible in their group before they are gone. For more information, see the Set alert trigger rules section of this manual.