Guides
Triage Alerts and Use Bulk Actions
Review alerts efficiently and resolve issues with bulk operations.
Triage Alerts and Use Bulk Actions
The Alerts page is the primary queue for incident response and alert lifecycle management. Effective triage means starting with the right summary mode, narrowing scope with filters, reviewing row-level context, and applying consistent state transitions in bulk when needed.
What to Click and Do Next
- In the sidebar, click
Operations > Alerts. - Choose summary mode:
Alert By Statusfor process-state handlingAlert By Severityfor impact-priority handling
- Use
Search alertsfor direct lookups. - Click
Viewto set time range. - Click
Filterand apply facets such asSeverity,Status,Workflow, orDevice. - Click an alert row to open detail context.
- Select multiple rows with checkboxes when repetitive updates are needed.
- Apply bulk action:
DismissResolveMark as Case Created
- If using
Resolve, select a reason and confirm.
Validate Outcome
- Confirm updated rows show expected status.
- Recheck counters with the same tab/range/filter state.
- Verify team reporting reflects intended resolution reasons.
Common Issues
- Counter and row mismatch due to changed tab, date range, or filters.
- Bulk actions unavailable because of role restrictions or alert state constraints.