Skip to main content
The Alerts tab in Case Management is your single triage queue. It pulls detections from every security tool you’ve connected into one list, so you can find what matters, understand it, and send it for investigation without hopping between consoles.

Find the Alerts That Matter

Narrow a noisy queue with the controls at the top of the list:
  • Filters — scope by status, time range, and severity.
  • Full-text search — match across alert fields to find a host, rule, or indicator.
  • Group by — collapse the list by host, severity, source, status, rule, operating system, user, or process to see patterns instead of a flat stream.
  • Auto-refresh — keep the queue current as new detections arrive.
  • Duplicate collapsing — repeated detections fold together so one noisy rule doesn’t bury everything else.

Read the Full Detection

Expand any alert to see the provider’s own detail — the raw fields exactly as the source reported them. For detections from Elastic Security, the expanded view includes the MITRE ATT&CK hierarchy, mapping the alert to its tactics and techniques so you can place it in the wider attack picture.

Act on What You Find

Send to Chat

Drop a single alert into the conversation to ask the AI about it in your own words.

Investigate / Enrich

Launch the Investigation Wizard on one alert to extract its indicators and hand it to the SOC agent.
Select several alerts and use bulk investigate to open a single investigation across all of them at once — useful when a group-by has revealed a cluster that belongs to the same incident.

Investigation Wizard

See how an alert becomes a structured investigation for Centurion’s SOC variant.
The Alerts tab is read-only triage. You filter, group, enrich, and route from here — you don’t change an alert’s status or export the queue. Response and documentation happen in chat, where you review and approve every action.

Where Alerts Come From

Any detection source you connect surfaces here. Representative providers include:
  • Elastic Security
  • Trend Micro Vision One
  • IBM QRadar
  • Wazuh
  • Rapid7 InsightIDR
  • CrowdStrike
  • Bitdefender
  • SentinelOne
  • Zabbix
  • Apura
  • Axur
Don’t see a source? Connect it first from Integrations, and its detections begin flowing into this queue. See the integration catalog.