Skip to content
User Guide

Review → IDS Alerts

IDS Alerts lets you browse and investigate the alerts your sensors have raised across the fleet. The page is visible to anyone who may view IDS evidence (app.sensors.execute), and alerts already collected stay readable even if the IDS Sensors add-on lapses.

A live banner announces new alerts that have arrived since you opened the view; click Refresh to pull them in.

What you can do

  • Browse alerts within your allowed locations, newest first.
  • Filter by sensor, severity, category, signature, IP, matched rule, and date range.
  • Open an alert to see its full payload from the sensor.
  • See which IDS-policy rule routed each alert, and whether it was notified or logged.

Filters

FilterMeaning
SensorShow alerts from one sensor.
SeverityShow alerts at a given severity.
CategoryShow alerts in a given category.
SIDShow alerts for one signature ID.
IPMatch the IP against either the source or the destination.
Matched RuleShow alerts routed by a specific IDS-policy rule.
From Date / To DateLimit to alerts within a time window.
SearchFree-text search box on the table.
ResetClear all filters.

The Sensor filter requires permission to view the sensor inventory. The Matched Rule filter requires permission to view IDS policy. You can browse alerts without either permission.

Table columns

ColumnNotes
TimeWhen the alert was raised.
SensorThe sensor that raised it.
SeverityAlert severity.
SignatureThe signature description and its SID.
CategoryThe signature’s category.
Src → DestThe source and destination endpoints as IP:port.
RoutingThe matched IDS-policy rule, with Notified / Logged indicators — or stored only when no rule matched.
ActionsView detail.

The table is paginated; sort by Time or Severity (other columns are not sortable).

Common tasks

Investigate an alert

  1. Optionally narrow the list with the filters above.
  2. Click the view action on the row.
  3. The detail dialog shows the full alert payload exactly as the sensor reported it.

Track new alerts as they arrive

When new alerts come in after you opened the page, the live banner at the top tells you how many. Click Refresh to load them into the table.

Alerts on a resource

When an alert’s source or destination IP belongs to a managed resource, the alert is automatically linked to that resource. A resource’s detail page then has an Alerts tab showing only the alerts that involve it. That tab replaces the Src → Dest column with a Role → Peer column — telling you whether the resource was the source or destination, and who the other endpoint was — and hides the Sensor and IP filters, since the view is already scoped.

Permissions

  • View retained alerts: app.sensors.execute.

Alert details require access to the sensor location recorded with the alert. Correlated sessions additionally require session-read permission and are filtered using the session evidence’s own access rules. Opening an alert from a resource page does not expand these permissions.