Chat now with support
Chat with Support

Change Auditor Threat Detection 7.0.1 - User Guide

Alert Filter

Use the Alert Filter pane to display a subset of alerts. The following is a list of the filter categories and values:

The filters are automatically applied as you make your selections. You can clear all currently set filters by clicking Clear.

How to perform an alert investigation

The alert investigation allows you to select existing alerts and indicators for investigation. From the Alerts tab, there are a few options available to start an investigation:

To follow the user to make its actions easier to track in the future, click the Watch Profile icon on the top right of the Alert Overview screen.

Common functions

There are many common functions that are used throughout the dashboard. Two of these are listed here for reference:

The Search User tool is located on the upper right corner of the dashboard. Using the tool, you can easily access alert investigations, and instantly drill down into their past behaviors.

If there is a user that you want to follow, you can add them to the list of watched users. You can quickly access the watched users from the Overview pane or by clicking the Watched icon in the All Users pane.

To start watching a user, click Watch Profile from their alert overview. To stop watching a user, click Stop Watching. You can also select to add more than one user by selecting Add all to Watchlist from the Users tab.

 

Alert and indicator reference

 

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating