Alert View Data

The Alert View screen provides general alert information.

Data

Description

Status

The current status of the alert or investigation triggered in Workbench

  • New: The alert is new and not currently under investigation

  • In progress: A user has begun investigating the alert

  • Closed: A user completed the investigation for the alert

  • Closed - true positive: After completing the investigation, the user concluded that this alert is a genuine threat to the organization and has decided to close the alert

  • Closed - false positive: After completing the investigation, the user concluded that this alert is a false positive and has decided to close the alert

  • Closed - benign true positive: After completing the investigation, the user concluded that this alert is a genuine threat but does not pose any risk to the organization, and has decided to close the alert

Score

The overall severity assigned to the alert

Trend Vision One calculates the score based on the severity of the matched detection model and the impact scope of the alert.

Note:

Starting on January 18, 2021, Trend Vision One has adjusted the scoring model and redefined the maximum alert score as 99. Only newly triggered alerts are affected.

The new scoring model takes the severity of the matched model as the dominant factor in calculation and defines a certain threshold for the impact scope value.

Workbench ID

The unique identifier for the alert

Model

The detection model that triggered the alert

For more information, see Detection Model Management.

Model severity

The severity assigned to a model that triggered the alert

Impact scope

The number of entities that the alert affects within the company network

Data source / processor

The product that is providing the data to the Workbench app

Created

The date and time Trend Vision One generated the alert

Associated incident

The ID of the incident that is associated with the alert

Click an incident ID to view detailed information.

For more information, see Incident Details.