Guides

Triage Alerts and Use Bulk Actions

Review alerts efficiently and resolve issues with bulk operations.

Triage Alerts and Use Bulk Actions

The Alerts page is the primary queue for incident response and alert lifecycle management. Effective triage means starting with the right summary mode, narrowing scope with filters, reviewing row-level context, and applying consistent state transitions in bulk when needed.

What to Click and Do Next

  1. In the sidebar, click Operations > Alerts.
  2. Choose summary mode:
    • Alert By Status for process-state handling
    • Alert By Severity for impact-priority handling
  3. Use Search alerts for direct lookups.
  4. Click View to set time range.
  5. Click Filter and apply facets such as Severity, Status, Workflow, or Device.
  6. Click an alert row to open detail context.
  7. Select multiple rows with checkboxes when repetitive updates are needed.
  8. Apply bulk action:
    • Dismiss
    • Resolve
    • Mark as Case Created
  9. If using Resolve, select a reason and confirm.

Validate Outcome

  1. Confirm updated rows show expected status.
  2. Recheck counters with the same tab/range/filter state.
  3. Verify team reporting reflects intended resolution reasons.

Common Issues

  • Counter and row mismatch due to changed tab, date range, or filters.
  • Bulk actions unavailable because of role restrictions or alert state constraints.