Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

PDF

Cisco Cyber Vision New UI Administration Guide, Release 5.6.0

Alerts

Want to summarize with AI?

Log in

Explains how alerts notify users about significant activity or irregularities in an industrial network, categorize data, and provide warnings to aid security monitoring.


Alerts are system-generated notifications that

  • indicate significant activity or irregularities detected within an industrial network,

  • categorize information based on type, associated data, and network components, and

  • provide warnings to help with security monitoring and response.

An alert is a notification that triggers when a user-defined rule’s condition is met. Cyber Vision sends alerts through Syslog when they are raised, cleared, or their status changes. For details about this configuration, see Enable or disable syslog notifications for an alert type.

Table 1. Feature History Table

Feature

Release Information

Feature Description

Pause and resume individual alert rules

Release 5.6.x

You can pause or resume individual alert rules. Pausing a rule does not affect other rules associated with the same alert type. Alert type-level pause and resume are no longer available.

MITRE ATT and CK information for Intrusion Detection alerts

Release 5.6.x

Intrusion Detection alerts display the MITRE ATT and CK tactics and techniques associated with the Snort rule that generated the alert.

Assets with unexpected behaviors alert type

Release 5.6.x

Cisco Cyber Vision monitors the assets that are part of the alert rules, and raises an alert when any of those assets are involved in selected behaviors within the configured time window.

Alert rule configuration changes

Release 5.6.x

You can no longer configure alert rules for functional groups. When you upgrade to Release 5.6.x, Cyber Vision automatically deletes existing alert rules configured for functional groups.

Network Scanner alert type

Release 5.6.x

The Network Scanner alert type identifies network reconnaissance and scanning attempts. IP addresses specified in the Allowed Scanner list are excluded and do not generate alerts.

Inactive assets alert type

Release 5.5.x

Inactive assets alert type detects assets that stop communicating due to failure or misconfiguration. Define custom rules for the inactivity period to reduce manual monitoring.

Intrusion detection alert type

Release 5.5.x

Intrusion detection alert type monitors network traffic using the Snort intrusion detection system. It raises an alert when suspicious or malicious network activity is detected on monitored assets, based on Snort rules.

Assets with unexpected external communications alert type

Release 5.5.x

Assets with unexpected external communications alert type monitors asset communications. It raises an alert if an asset communicates to external IP addresses or domains.

Network-based organization hierarchy alert configuration

Release 5.4.x

You can configure alerts at the organization hierarchy level with one additional entity type: Organization Hierarchy (Networks).

The system changes all existing alert rules with the entity type Organization Hierarchy to Organization Hierarchy (Sensors) automatically.

Mute or unmute alert instances for prohibited vendor alert type

Release 5.4.x

You can use the mute and unmute feature to control prohibited vendor alerts. Mark alert instances as reviewed and not urgent so they remain in the system but are not active. Select the duration to mute an alert instance; after that period, the alert becomes active again.

Active and cleared alerts

Release 5.3.x

The Alerts page displays two types of alerts:

  • Active

  • Cleared

Pause alert creations

Release 5.3.x

You can pause an alert type in the Configure > Alerts

Change vulnerability scoring system for alerts

Release 5.3.x

The Cisco Security Risk Score is the default scoring system applied to alert configurations. However, you can choose to update an alert configuration to apply the CVSS scoring system instead.

Alert for severe vulnerabilities in monitored entities

Release 5.3.x

Create and edit rules for the Severe vulnerabilities in monitored entities alert based on the Cisco Security Risk Score or the CVSS score.

Alert for prohibited vendors

Release 5.3.x

The Configure > Alerts page contains a default alert for prohibited vendors. The alert rule is based on an editable list of prohibited vendors.


Alert types

Cyber Vision provides alert types that monitor security conditions and activity across your assets and network. Each alert type contains rules that define what Cyber Vision monitors and when it generates alerts. To view and configure alert types and rules, choose Configuration > Alerts.

Alert type

Description

Severe vulnerabilities in monitored entities

Prohibited vendors

  • Cyber Vision triggers alerts when your assets are linked to prohibited vendors.

  • The default rule for this alert type is Prohibited_list.

Inactive assets

  • Cyber Vision automatically detects assets that have stopped communicating due to failure or misconfiguration. It then alerts you about the issue.

  • Define rules to set the inactivity threshold for triggering alerts, reducing manual monitoring.

Intrusion Detection

  • This alert type monitors network traffic using the Snort intrusion detection system. Enable Intrusion Detection System (IDS) on a compatible sensor to activate Snort-based intrusion detection. See Enable IDS on a sensor.

  • The default rule for this alert type is Default_Snort_Global.

  • Detects suspicious network activity identified by Snort rules. When mapping information is available, the alert displays the associated MITRE ATT and CK tactics and techniques.

Assets with unexpected external communications

  • This alert type raises an alert if assets communicate with external IP addresses.

  • The default rule for this alert type is Default_Monitored_Asset_Types, which monitors external communications for all assets with type PLC, IED, or IO.

Network Scanner

  • Cisco Cyber Vision triggers alert when it detects network reconnaissance and scanning activity such as:

    • Vertical scan - One source IP scans multiple ports on a single target host.

    • Horizontal scan - One source IP scans a single port across multiple hosts.

    • Combined scan - Combination of vertical and horizontal scanning, where multiple ports on multiple hosts are scanned.

    • Industrial scan - Scan targets industrial protocol traffic and anomaly detection specific to operational technology (OT) environments.

    • Burst scan - Large number of scan attempts in a very short period.

    • Targeted scan - Focused reconnaissance against specific high-value assets.

  • The default rule for this alert type is Default_Scan_Global.

Assets with unexpected behaviors

Cisco Cyber Vision triggers an alert when an asset that is part of the alert rule is involved in one of the selected behaviors, in the configured role, within the configured time window.


Alert states and key attributes

Cyber Vision manages alerts by tracking their progression through defined states. Alerts are organized by type, and rules specify when and how alerts are triggered.

How Cyber Vision organizes alerts

Cyber Vision organizes alerts by alert type, rule, trigger, instance, and occurrence. An alert rule defines the monitored condition. A trigger identifies the condition that generated the alert. An instance identifies an affected entity or activity. An occurrence records each time Cyber Vision detects that condition for the instance.

Alert states

You can monitor alerts as they move through distinct states:

  • Active: Displays current unresolved alerts. Alerts stay active while the underlying problem exists.

  • Muted: When you mute alert instances related to the Prohibited vendors, Inactive assets, Intrusion Detection, Assets with unexpected behaviors, and Assets with unexpected external communications alert types, those alerts appear in the Muted tab.

  • Cleared: After you resolve alerts, they appear in the Cleared tab. Cyber Vision keeps cleared alerts for a set number of days before removing them. The retention period is different for each type of alert. You can manually clear alert instances only for the Inactive assets, Network Scanner, Assets with unexpected behaviors, and Assets with unexpected external communications alert types.

Alert details

To view the alert details, from the main menu choose Alerts.

Name

Description

Alert Type

Specifies the category of alert generated by the system. Each type shows the nature of the underlying issue detected.

Trigger

Identifies the condition or detected object that caused the alert rule to generate an alert. The displayed information depends on the alert type.

Instances

Identifies an entity or activity affected by the trigger. One trigger can have multiple instances.

Occurrence

Records each time Cyber Vision detects the alert condition for an instance.

Severity

Severity levels include Critical, High, Medium, and Low. Use these levels to prioritize your response.

Triggered By

The alert category triggers the alert.

Last Detected

Shows the date and time when the alert was last triggered.

Note
  • The Alerts dashboard for the Assets with unexpected external communications alert type is relevant for last month only.

  • The trigger, instance, and occurrence information displayed in the Alerts page depends on the alert type.

Alert information by alert type

Alert type

Trigger

Instance

Occurrence

Severe vulnerabilities in monitored entities

A vulnerability that meets the configured scoring threshold

An asset affected by the vulnerability

A detection of the vulnerability on the asset

Prohibited vendors

A vendor included in the prohibited-vendor list

An asset associated with the prohibited vendor

A detection of the prohibited vendor on the asset

Network Scanner

Network reconnaissance or scanning activity from an asset or IP address that is not on the Allowed scanners list.

A target asset scanned by that source IP address.

A detection of scanner activity on the target asset, including the scanned ports.

Assets with unexpected behaviors

A behavior detected on a monitored asset.

A monitored asset that participates in the behavior in the role specified by the alert rule: Initiator, Target, or Both.

Each detection of the selected behavior involving that monitored asset during the rule’s configured time window.

Inactive assets

An alert rule whose configured inactivity threshold is met.

An asset that has stopped communicating.

A detection that the asset has remained inactive for the configured duration.

Intrusion Detection

A Snort rule that detects suspicious or malicious network activity.

A source asset involved in traffic that matches the Snort rule.

Each detection of the Snort rule involving the source asset.

Assets with unexpected external communications

A monitored asset that communicates with an external address or domain.

An external IP address or domain contacted by the monitored asset.

Each detected communication between the monitored asset and the external address or domain.


MITRE ATT and CK information for Intrusion Detection alerts

Use the MITRE ATT and CK information in an Intrusion Detection alert to understand the objective and method of the activity detected by a Snort rule.

MITRE ATT and CK mapping

Cyber Vision maps the Snort rule that generates an Intrusion Detection alert to the corresponding MITRE ATT and CK tactics and techniques.

A Snort rule uses a GID:SID pair to identify the generator and signature that detected the activity. When a MITRE ATT and CK mapping exists for the GID:SID pair, Cyber Vision displays the mapped information in the alert preview and summary.

Cyber Vision displays the MITRE ATT and CK information in the following locations:

  • The expanded alert preview displays the associated MITRE ATT and CK tactics.

  • The alert Summary tab displays the GID:SID pair and the associated MITRE ATT and CK tactics and techniques.

  • A tooltip displays the technique name when you hover over a MITRE ATT and CK technique ID.

Note

A Snort rule can map to one or more MITRE ATT and CK tactics. Each tactic can include one or more techniques.

MITRE ATT and CK alert details

From the main menu, choose Alerts, expand an Intrusion Detection alert, and click View alert summary.

Table 2. MITRE ATT and CK information

Field

Description

GID:SID

Identifies the Snort generator and signature that generated the alert.

MITRE ATT and CK Tactic

Identifies the objective that the detected activity attempts to achieve.

MITRE ATT and CK Technique

Identifies how the detected activity attempts to achieve the objective. Hover over a technique ID to view the technique name.


Supported actions for alert rules

Identify the management actions that Cyber Vision supports for each alert rule type.

Alert type Permitted alert rule actions

Severe vulnerabilities in monitored entities

Create, edit, duplicate, delete, pause, or resume alert rules.

Prohibited vendors

Edit, pause, or resume the alert rule.

Inactive assets

Create, edit, delete, pause, or resume alert rules.

Assets with unexpected external communications

Create, edit, duplicate, delete, pause, or resume alert rules.

Intrusion Detection

Pause or resume the default alert rule. You cannot create, edit, duplicate, or delete the default alert rule.

Network Scanner

Edit, pause, or resume the alert rule.

Assets with unexpected behaviors

Create, edit, duplicate, delete, pause, or resume alert rules.


Pause or resume individual alert rules

Starting from Cisco Cyber Vision Release 5.6.x, you can pause or resume individual alert rules.

Pausing an alert rule temporarily stops that rule from generating new alerts. Other rules associated with the same alert type remain active.

Here are few things for you to consider before pausing or resuming individual alert rules.
  • Resuming a paused alert rule allows it to generate new alerts again.

  • Pause and resume actions are no longer available at the alert-type level.

    Migration note: When you upgrade from Release 5.5.x to Release 5.6.x, Cyber Vision sets every rule associated with a paused alert type to Paused. After the upgrade, resume individual rules as needed.


Pause or resume individual alert rules

Pause one or more alert rules to temporarily stop them from generating new alerts, or resume paused rules to restart alert generation.

Pausing an alert rule affects only the selected rule. Other rules associated with the same alert type remain active. Pausing a rule does not change existing alerts.

Before you begin

  • Ensure that your user role allows you to manage alert rules.

  • Identify the alert type and rules that you want to pause or resume.

Procedure

  1. From the Cisco Cyber Vision main menu, choose Configuration > Alerts.

  2. Select an alert type.

  3. Select the check boxes for one or more alert rules that you want to pause or resume.

  4. Click Pause or Resume.

  5. Confirm the action if prompted.

When you pause the selected alert rules, Cyber Vision stops generating new alerts for those rules. Existing alerts remain unchanged. Other rules associated with the same alert type remain active.

When you resume the selected alert rules, Cyber Vision allows them to generate new alerts again.

The status of each selected rule changes to Paused or Active.


Create alert rules for severe vulnerabilities in monitored entities

Enable proactive vulnerability monitoring by creating alert rules that trigger notifications for severe vulnerabilities within monitored assets.

Starting with Release 5.6.x, you cannot configure alert rules for functional groups. When you upgrade to Release 5.6.x, Cyber Vision automatically deletes existing alert rules configured for functional groups.

Create alert rules under the Severe vulnerabilities in monitored entities alert type to automatically notify you when assets meet specific vulnerability criteria. This helps ensure timely response to critical security threats.

Procedure

  1. From the main menu, choose Configuration > Alerts.

  2. Select the Severe vulnerabilities in monitored entities alert type.

  3. Click Create new rule.

  4. Enter an Alert Rule Name, select the Severity and Entity type.

    Entity types:

    • Organization Hierarchy (Sensors): Triggers alerts for assets linked to sensors assigned to the selected organization hierarchy levels.

    • Organization Hierarchy (Networks): Triggers alerts for assets linked to networks assigned to the selected organization hierarchy levels.

  5. On the Entity selection page, select the organization hierarchy levels.

    • If you select assets based on organization hierarchy (Networks), check Assets seen in Unknown networks to include unidentified or unmapped assets.

    • If you select assets based on organization hierarchy (Sensors), check Assets seen by Unknown data sources to include unidentified or unmapped assets.

    Note

    The available Entity selection options depend on the Entity type you select in the Rule name and entity type step.

  6. In the Scoring system and threshold tab, select one scoring system:

    • For Cisco Security Risk Score, enter a threshold number between 34 and 100.

    • For CVSS, enter a threshold number between 7 and 10.

    Note

    Cisco Security Risk Score is the default, but you can select CVSS.

  7. Review your selections in the Summary and click Save.

The new alert rule appears on the Configuration > Alerts > Severe vulnerabilities in monitored entities page. You receive alerts when asset vulnerabilities match the new rule.

What to do next

  • Regularly review the Configuration > Alerts page to manage and update alert rules as needed.

  • To manage alert rules, navigate to Configuration > Alerts, select an alert type, and choose to edit, duplicate, or delete actions.


Create an alert rule for inactive assets

You receive timely notifications and can take action when assets have not communicated for a set timeframe.

You can monitor asset activity and automatically generate alerts when assets are inactive for longer than a set threshold.

Before you begin

Identify the assets you want to monitor.

Procedure

  1. From the main menu, choose Configuration > Alerts.

  2. Select the Inactive assets alert type.

  3. Click Create new rule.

  4. Specify the Alert Rule Name, Severity, and the timeframe for inactivity (Since inactive).

    Note

    You will receive an alert if an asset does not communicate within the selected period.

  5. Select the assets you want to monitor.

  6. View the summary and click Save.

When an asset is inactive for the specified period, the system triggers an alert. The Alerts page displays a summary of the alert and its instances.


Create an alert rule for external communications

You can establish an alert rule that enables the detection and notification of any monitored asset communicating externally, ensuring timely identification and response to potential security risks.

When an asset communicates with external IP addresses or domains, the alert rule triggers a notification in the Alerts dashboard. This allows you to manage asset security proactively.

Procedure

  1. From the main menu, choose Configuration > Alerts.

  2. Select the Assets with unexpected external communications alert type.

  3. Click Create new rule.

  4. Enter an Alert Rule Name and select Severity and Entity type.

    Entity types include:

    • Organization Hierarchy (Sensors): Triggers alerts for assets linked to sensors assigned to the selected organization hierarchy levels.

    • Organization Hierarchy (Networks): Triggers alerts for assets linked to networks assigned to the selected organization hierarchy levels.

    • Asset Types: Triggers alerts for assets linked to the selected asset types.

  5. Select the relevant organization hierarchy levels or asset types in the Entity selection page.

    To include unidentified or unmapped assets:

    • Select Assets seen by Unknown data sources for the Organization Hierarchy (Sensors) entity type.

    • Select Assets seen in Unknown networks for the Organization Hierarchy (Networks) entity type.

    Note

    The available Entity selection options depend on the Entity type you select in the Rule name and entity type step.

  6. Review your selections in the Summary and click Save.

The new alert rule appears under Configuration > Alerts > Assets with unexpected external communications alert type.

What to do next

  • Regularly review the Configuration > Alerts page to manage and update alert rules as needed.

  • Navigate to Configuration > Alerts, select the alert type, and choose the appropriate action to edit, duplicate, or delete alert rules.


Configure allowed scanner IP addresses for the Network Scanner alert rule

Use this task to manage allowed scanner IP addresses for Default_Scan_Global, the default Network Scanner alert rule.

Adding IP addresses under Allowed scanners exempts them from detection and alert generation. Port scans from IPs not included as Allowed scanners will trigger a new alert instance.

Follow these steps to configure allowed scanner IP addresses for Network Scanner alert rules:

Procedure

  1. From the main menu, choose Configuration > Alerts.

  2. On Alerts, select Network Scanner.

  3. In Alert Rules, select Default_Scan_Global and then select the Edit under Actions.

  4. On Rule name and severity, keep the default values and click Next.

  5. Under Allowed scanners, enter an IP address in Allowed scanner IP, or search by asset name and select the associated IP address. Then click Add.

  6. Click Next to open Summary.

  7. Review the Allowed scanners count and IP address selection, then click Save.

The system updates Default_Scan_Global with the specified allowed scanner IP addresses. Port scans from these addresses are exempt from detection and do not trigger alerts.

What to do next

Next, from the main menu, select Alerts and review alerts for Network Scanner alerts generated by scanner activity that is not exempt from detection. Open an alert and review Summary to identify the scanner, scanned targets, and scanned ports. View alerts in a table and export them to a CSV file if you need to retain a trace.

Under Assets, open the scanner asset for more details, then review the alert from its Alerts tab.


Asset behavior alerts

The Assets with unexpected behaviors alert type raises alerts when selected assets participate in a behavior selected in an active rule during its configured time window. Unexpected asset behavior refers to behavior that matches a rule you configured for this alert type.

  • A rule specifies the assets to monitor, their required role for behavior, the behaviors to watch, a time window, and an alert severity.

    Note

    The time window can be from 1 to 30 days. The default is 7 days.

  • An alert is raised when a matching behavior is observed. If Syslog notification is enabled for the alert type, Cisco Cyber Vision also sends a corresponding event to the configured Syslog server.

Asset roles for behavior

An asset behavior describes a meaningful action inferred from network communications, for example, Program Download, Restart CPU, Read Var, and so on. Every behavior has two roles:

  • Initiator (source) - The asset that performs the behavior.

  • Target (destination) - The asset on which the behavior is performed.

Note

Some behaviors are role-agnostic. They match only rules configured for both initiator and target roles.

Table 3. Asset roles for behavior alert rules

Rule role

Use it when

Example

Initiator

The configured assets must perform the selected behavior.

Monitor a jump host that initiates an OT command.

Target

The configured assets must receive the selected behavior.

Monitor a PLC that receives a program change.

Both

Either role is meaningful, or you need to include role-agnostic behaviors.

Monitor a critical asset that participates in either role.


Create an alert rule for unexpected asset behaviors

Create a focused alert rule to monitor behaviors that have a clear operational or security purpose.

The alert rule includes steps for specifying identity, scope, entities, time window, and behaviors, and for conducting a final summary review.

Follow these steps to create an alert rule for unexpected asset behaviors.

Procedure

  1. From the main menu, choose Configuration > Alerts.

  2. Select Assets with unexpected behaviors, then click Create new rule.

  3. Under Rule name and entity type ,

    1. Enter a descriptive Alert Rule Name.
    2. Select the Severity.
      Note

      Choose severity based on operational consequence, not protocol alone.

    3. Select one Entity type:
      • Organization Hierarchy (Sensors): Triggers alerts for assets linked to sensors assigned to the selected organization hierarchy levels.

      • Organization Hierarchy (Networks): Triggers alerts for assets linked to networks assigned to the selected organization hierarchy levels.

      • Assets: Triggers alerts for assets linked to the selected asset types.

    4. Click Next.

    The selected severity applies to every instance raised by the rule.

  4. Under Entity selection,

    1. Select the relevant organization hierarchy levels or asset types.
      Note

      The available Entity selection options depend on the Entity type you select in the Rule name and entity type step.

      • If you select assets based on organization hierarchy (Networks), check Assets seen in Unknown networks to include unidentified or unmapped assets.

      • If you select assets based on organization hierarchy (Sensors), check Assets seen by Unknown data sources to include unidentified or unmapped assets.

      • If you select Assets, you can filter assets by name, IP address, MAC address, or network. Verify the selection counter before you continue; a filter narrows the visible table but does not remove previously selected assets.

    2. Click Next.
  5. Under Time window and scope,

    1. Set the lookback window in Time window. The default time window is 7 days. You can set the time window from 1 to 30 days.
      Tip

      A longer window keeps infrequent behaviors active. A shorter window makes alerts clear sooner after the last observation.

    2. Under Match configured assets as, select the asset role:
      • Target: The behavior is performed on the selected asset.

      • Initiator: The selected asset performs the behavior.

      • Both initiator and target: Both initiator and target roles match.

    3. Click Next.
  6. Under Behaviors,

    1. Select one or more behaviors from the catalog. Use search as needed, and switch between Important behaviors and Other behaviors to review the category and description of each behavior.
      Note

      Important behaviors are visually emphasized in alerts. Their importance does not override the severity you assign to the rule.

    2. Click Next.
  7. Under Summary, review the rule name, severity, entity type, selected entities, time window, role, and behaviors, then click Save.

Evaluation starts automatically. Matching observations already present within the configured time window can produce alerts without waiting for a new packet.


Verify asset behavior alerts instance

Review active asset behavior alert instances to determine their origins, affected targets, observed behaviors, and associated rule context.

Asset behavior alerts in Cisco Cyber Vision remain active as long as the triggering behavior persists within a matching rule’s time window. An alert clears when no running rule matches. This occurs, for example, when observations age out, or when the rule, asset, behavior, or applicable role changes.

  • Alerts are grouped by their source asset, even when the configured assets are targets. Each instance identifies the target asset and behavior.

  • If several rules match the same source, target, behavior, and orientation, Cisco Cyber Vision displays one instance and lists the applied rules.

Follow these steps to verify asset behavior alerts instance.

Procedure

  1. From the main menu, select Alerts and click the Active tab.

    You can select the Muted or Cleared tab to review alerts in those states.

  2. Locate and expand the Assets with unexpected behaviors alert that you want to review.

    Alert rows are grouped by source asset. This arrangement keeps the potential initiator visible as the alert trigger. Each instance also identifies the exact target and behavior.

  3. Click View alert summary to view the behavior and the corresponding source or target details.

  4. Click the Instances tab and review each column:

    • Source asset - shows the initiator.

    • Target asset - shows the destination.

    • Behavior - displays the observed action.

    • Severity - indicates the applicable rule severity.

    • Alert Rules - lists the number of matching rules.

    • Last Detected - shows the most recent observation.

    Note

    Repeated observations update the existing instance and its last-detected time. They do not create a new row for each occurrence.

  5. Under Alert Rules, click the count to open the instance drawer and review comprehensive details: behavior, both source and target assets, available type, vendor, addresses, networks, sensors, applied rule, severity, configured role, and time window.

    For a target-oriented rule, the configured asset appears under Target asset. The source remains the initiator and is the starting point for review.

You can identify the observed behavior, affected assets, and rule context that produced each alert instance.


Mute alert instances

Temporarily suppress non-critical alert instances so you do not need to review known, non-urgent alerts repeatedly.

Mute alerts for Prohibited vendors, Inactive assets, Intrusion Detection, Assets with unexpected behaviors,and Assets with unexpected external communications alert types. This helps you focus on critical issues. The mute feature marks specific asset alerts as reviewed and not urgent. Muted alert instances remain in the system and are inactive until the mute period ends.

Procedure

  1. From the main menu, choose Alerts.

  2. On the Active tab, find the relevant alert type and click the alert Instances count.

  3. Select the alert instances you want to mute.

  4. Click Mute.

  5. Select the mute duration.

    • You can select from three available durations: Forever, For 7 days, or For 30 days.

    • To specify a custom period, select Custom and enter a number of days from 1 to 180.

    Note

    After the selected mute duration (except for Forever), alerts become active again.

  6. (Optional) Add a comment.

  7. Click Mute to confirm.

Muted alerts move from the Active tab to the Muted tab.

What to do next

  • To unmute an alert instance, go to Alerts > Muted, select the alert instance, and click Unmute.

  • After you unmute, the instance drawer of the active alert shows when it was last muted.


Clear alerts for specific assets

Clear resolved alerts from assets so the alert dashboard reflects current alerts only.

Perform this task when asset-related issues are resolved, but the system still lists alerts for those assets. Clearing alerts helps maintain accurate alert tracking.

Procedure

  1. From the main menu, choose Alerts > Active.

  2. Click the instance count for either the Inactive assets, Network Scanner, Assets with unexpected behaviors, or Assets with unexpected external communications alert types.

  3. Select the asset you want to clear alerts for.

  4. Click Clear.

After you clear alerts, the system moves the selected alert from the Active tab to the Cleared tab to show that its alerts are cleared.