| Term | Meaning |
|---|---|
| Alert | One detection matching one entity in one window. |
| Correlation | A cluster of related alerts sharing entities, which can be escalated into a case. |
| Case | The investigation workspace an alert or correlation escalates into. The console's only meaning of incident. |
| Organization | A tenant; typically one legal entity you protect. |
| Entity | The thing an alert is about: a host, a user, an address, a hash. |
| Detection, rule | The query, sequence or correlation that raises alerts. |
| Content pack | The detections shipped with the platform. |
| Playbook, workflow | Blocks that run on an alert: enrich, decide, respond, notify. |
| Pre-stage, auto | Playbook modes: propose for confirmation, or execute within the ceiling. |
| Ceiling | The most consequential automatic action allowed for an organization. |
| Verdict | The advisory AI conclusion on an alert, with confidence, recommendation and evidence grade. |
| Evidence grade | How much of the cited evidence is actually about the alert. |
| Suppression | A pre-alert filter across rules, with a reason and a counter. |
| Exception | A negation compiled into one rule. |
| Fleet group | A set of hosts sharing a policy. |
| Support tier | A, B or C: the capabilities available on a given platform version. |
| Ingest key | A per-organization bearer key for HTTP and HEC senders. |
| Unparsed queue | Where events that could not be normalised wait, visibly. |
| Portal | The customer-facing application. |
| Standing | The customer's summary view in the portal. |
Glossary
The words the console uses, defined once.