Enterprise Alert Categories

The Enterprise Alert Categories widget in the CISO Overview optic shows the top 6 alert categories with the most alerts over the specified time and filters. Each alert corresponds to a category. For example, categories might include malicious activities, unauthorized access attempts, policy violations, and so on. Grouping alerts based on categories provides insights into the nature of security risks faced by organizations and helps you prioritize actions.

As shown in the preceding image, each alert category in the widget displays the following information:

1 - Name of the alert category.

2 - Total number of alerts in the category.

3 - Percentage change in the alert count when compared to the previous time frame.

4 - Alert trend over the specified time.

Mouse over the trend line to view the following details:

Analyzing Alerts in an Alert Category

When you click the total alert count in a category, a fly-out pane displays the distribution of alerts by alert type.

As shown in the preceding image, the fly-out pane displays the following information:

Expand an alert type as shown in the following image to explore all alert instances under the alert type.

As seen in the preceding image, the following information is displayed: