Review → IDS Alerts
IDS Alerts lets you browse and investigate the alerts your sensors have raised across the fleet. The page is visible to anyone who may view IDS evidence (app.sensors.execute), and alerts already collected stay readable even if the IDS Sensors add-on lapses.
A live banner announces new alerts that have arrived since you opened the view; click Refresh to pull them in.
What you can do
- Browse alerts within your allowed locations, newest first.
- Filter by sensor, severity, category, signature, IP, matched rule, and date range.
- Open an alert to see its full payload from the sensor.
- See which IDS-policy rule routed each alert, and whether it was notified or logged.
Filters
| Filter | Meaning |
|---|---|
| Sensor | Show alerts from one sensor. |
| Severity | Show alerts at a given severity. |
| Category | Show alerts in a given category. |
| SID | Show alerts for one signature ID. |
| IP | Match the IP against either the source or the destination. |
| Matched Rule | Show alerts routed by a specific IDS-policy rule. |
| From Date / To Date | Limit to alerts within a time window. |
| Search | Free-text search box on the table. |
| Reset | Clear all filters. |
The Sensor filter requires permission to view the sensor inventory. The Matched Rule filter requires permission to view IDS policy. You can browse alerts without either permission.
Table columns
| Column | Notes |
|---|---|
| Time | When the alert was raised. |
| Sensor | The sensor that raised it. |
| Severity | Alert severity. |
| Signature | The signature description and its SID. |
| Category | The signature’s category. |
| Src → Dest | The source and destination endpoints as IP:port. |
| Routing | The matched IDS-policy rule, with Notified / Logged indicators — or stored only when no rule matched. |
| Actions | View detail. |
The table is paginated; sort by Time or Severity (other columns are not sortable).
Common tasks
Investigate an alert
- Optionally narrow the list with the filters above.
- Click the view action on the row.
- The detail dialog shows the full alert payload exactly as the sensor reported it.
Track new alerts as they arrive
When new alerts come in after you opened the page, the live banner at the top tells you how many. Click Refresh to load them into the table.
Alerts on a resource
When an alert’s source or destination IP belongs to a managed resource, the alert is automatically linked to that resource. A resource’s detail page then has an Alerts tab showing only the alerts that involve it. That tab replaces the Src → Dest column with a Role → Peer column — telling you whether the resource was the source or destination, and who the other endpoint was — and hides the Sensor and IP filters, since the view is already scoped.
Permissions
- View retained alerts:
app.sensors.execute.
Alert details require access to the sensor location recorded with the alert. Correlated sessions additionally require session-read permission and are filtered using the session evidence’s own access rules. Opening an alert from a resource page does not expand these permissions.