Customizing alert severity

VIDEO  Learn how to customize alert severity.

Sometimes, it's convenient to change the Alert Severity from Critical to Medium or Low or from Medium to Low, depending on customers' needs and behavior. 

Setting the Alert Severity to Low will not send alert notifications to your PSA or email. However, it will be logged within Realtime Alerts with a severity of Low. For future reference, SaaS Alerts analysis will allow you to review the alert if need be.

Changing the severity of Critical Alert or Alert to Low (Logged Event) will prevent the event from generating a ticket (in email/PSA).

Changing the severity of an event will only affect future events. Past events will keep their original severity.

  • To customize Alert Severity, from the main SaaS Alert Window, select the Settings tab and select Customize Alerts

2024-06-21 15_26_41b-.png

  • Look for the alert you want to customize.  You can search for a keyword of the name of the alert you want to change, for example, search (Ctrl+F, command+F) for the word "limit" or "File" to find Alert suppressed as an example and change the alert to Critical, Medium or Low from the drop-down menu under Custom Severity.
  • Your account must have Administrator Privileges in SaaS Alerts to Change Alert Severity
  • To see the whole list of Alerts, make sure you scroll down to select additional rows to view.

2024-06-21 15_36_16-SaaS Alerts! — Mozilla Firefox.png

2024-06-21 15_39_13-.png

Restoring Alerts Severity To Default

To set the File Alert Severity or any other Alert Severity back to default, click on the Reset Item button next to the alert you want to restore or click on the Reset All Items button at the top of the Customize Alert Severity table to set all the alerts back to default.

2024-06-21 15_56_37-.png

Due to the growing size of the alerts library, over 280, SaaS Alerts has reviewed and determined a new schema for the default severity of these alerts. The new default, called Quiet Mode, takes into consideration the noise the system can generate and has reduced this. The intent being that Unify, Fortify and Respond can be leveraged to tighten controls and act upon possible threats.

Upon review of the changes we encourage all Partners to adopt the Quiet default. This new default will not override any current customized alert severities. Navigate to Settings → Customize Alert Severity. At the top there is a toggle for Onboarding Mode and Quiet Mode.For further explanation of Quiet Mode Default Severity for Alerts, please see our KB Article:

Quiet Mode Default Severity for Alerts