Skip to main content

Alert List

The alert management page provides an alert-centric view independent of incidents, where you can see detailed information about all alerts regardless of whether they have been grouped into incidents. Go to Incident ListAlert List to access the alert management page. The alert list displays the following information:
ColumnDescription
SeverityDisplays alert severity as a color bar (Critical, Warning, Info)
TitleAlert title description
Processing StatusWhether the alert is closed (Closed / Not Closed)
Recovery StatusWhether a closed alert has auto-recovered (Recovered / Not Recovered)
DurationTime elapsed from alert trigger to current time or closure
Associated EventsNumber of raw events associated with the alert
Associated IncidentThe incident this alert belongs to; click to navigate to incident details
Trigger TimeWhen the alert was first triggered
Integration SourceIntegration name and type (shared or dedicated) that the alert originated from
ChannelThe channel this alert belongs to
Silenced or inhibited alerts display a special marker before the title to help you quickly identify them.
The top of the alert list provides rich filtering capabilities, similar to the incident list, supporting filtering by time range, severity, labels, and other conditions. Filter conditions are saved in local storage and persist after page refresh.

Batch Operations

You can select multiple alerts in the list for batch operations, such as batch closing.

Using Aggregate View

In addition to the standard list view, the alert list also supports Aggregate View. Aggregate view groups alerts by specified dimensions, displaying group cards on the left and alert details for the selected group on the right.
1

Create aggregate view

After switching to aggregate view, if no aggregation rules have been created, the system guides you to create your first aggregate view.
2

Select grouping dimension

Select the aggregation rule for grouping. The system groups alerts by that dimension.
3

Browse groups

The left panel shows group cards including group title, severity, and alert count. Click a group card to display all alerts in that group in the right panel.
In aggregate view, the system matches at most 100 records for grouping display. To view full data, switch to list view.

Alert Details

Click an alert title to enter the alert details page. The alert details page provides three tabs:
TabDescription
Alert OverviewShows alert description, labels, attributes (channel, duration), images, alert status timeline (trigger and close time), alert source, associated incident, and Links
TimelineShows all event records throughout the alert lifecycle
Associated EventsShows the list of all raw events associated with this alert
The top of the alert details page displays key information including title, severity, processing status, short ID, and provides action buttons for closing, merging, etc.
You can also choose to view details in the Side Panel mode from the alert list view settings, allowing you to quickly browse alert information without navigating to a new page.