Notifications

The console inbox, per-analyst preferences, organization routing and the delivery log.

The inbox

The bell in the top bar is an inbox of what the platform raised for you and for the organizations in your scope. Each notification links to the alert, case, ticket or host it is about. Notifications opens the full list with a Delivery view showing what was sent, where, and whether it succeeded.

Kinds

KindRaised when
Alert criticalA critical alert is written.
SLA approachingAn alert reaches the approach threshold.
SLA breachedAn alert passes its target.
Assigned to youSomeone assigns you an alert or case.
MentionedSomeone @-mentions you in a note or the war room.
Case updateA case you own changes state.
Response stagedA playbook has staged an action awaiting confirmation.
Response executedAn automatic action ran.
Containment tamperedAn isolated host's firewall state changed unexpectedly.
Source stalledA connector or sender stopped delivering.
TicketA customer opened or replied to a ticket.
Report publishedA report was published to a portal.

Preferences

Settings › Notifications lets each analyst choose which kinds reach the inbox, email or a channel, and quiet hours. An organization's mute in Settings › Organizations wins over any individual choice.

Organization routing

Per organization, admins set extra recipients on the operator side, the customer recipients for portal notifications, muted kinds and the customer's quiet hours.

Channels

Email, Slack, Microsoft Teams, Discord and webhooks are configured as egress integrations and can be selected per kind. See Egress.