Managing Alerts

The Alerts page provides information about alerts enabling administrators to view and manage activity alerts in the Web Console. If configured as the default user page, the Alerts page will open by default when the user logs on to the Web Console. See Creating and Managing Local Console Users.

You can print the Alerts list and/or export it to Excel. Alerts can be deleted ONLY by ObserveIT Administrators.

Important: Alerts are triggered by alert rules which define the conditions that could signify suspicious user activity on ObserveIT monitored endpoints. ObserveIT administrators can create and manage alert rules from the Alert & Prevent Rules page (by selecting Configuration > Alert & Prevent Rules in the ITM On-Prem Web Console). For details, see Managing Rules.

To open the Alerts page

  • In the ITM On-Prem Web Console, click Management Console, then Alerts.

    The Alerts page opens in List view (the default mode), displaying a list of triggered alerts according to the default specified time period, alerts' status, risk level, rule type, OS type, and other filtered criteria.

The number of alerts on the page out of the total number of alerts is displayed. By default, the page shows up to 20 alerts; you can change the default by selecting 50 or 100 from the Items per page drop-down list above the table.

Alert Viewing Modes

You can view alerts in different modes. To switch between modes, click the required icon in the area.

List view

In this view, you can see at a glance all the alerts that are already configured according to the specified filter criteria.

Details view

In this view, you can see for each alert exactly Who? Did What? On Which Computer? When? and From Which client?

Gallery view

The Gallery view provides a slideshow of the screenshots for each alert alongside the alert's details.

By viewing alerts in this mode, you can see clearly the user environment and the context of exactly what the user was doing when an alert was triggered.

Click the icon next to an alert to open Ongoing Alerts Tuning where you can perform several quick alert tuning actions.

Activity Alert Tasks

The tasks you can perform on alerts include: