Alert Details
Limited Availability
Agentic SOC is available to a limited set of US-based customers as part of a Limited Availability release. If you don’t see the Signals or Alerts pages described in this documentation, your organization hasn’t yet been migrated to Agentic SOC. Your existing Alerts and Investigations experience remains unchanged until migration.
Expanded Event Source Required
To use autonomous investigation, Playbook, AI Overview, and AI determination, you must configure the Microsoft Cloud, CrowdStrike Falcon, and SentinelOne EDR Expanded Cloud event sources. Standard (non-expanded) configurations do not provide the telemetry these features require.
The Alert Details page is the full detail view for a single Alert. It brings together all investigation data (AI findings, raw evidence, entity context, response history, and analyst activity) in a tabbed layout so you have everything you need to understand and act on a security event without leaving the page.
To open the Alert Details page, select an Alert from the Alerts table and click the open full page icon, or click directly on the Alert title.
Alert header
At the top of the Alert Details page, a persistent header displays the Alert’s core attributes. These fields stay visible regardless of which tab you’re on, and privileged users can update them directly from the header:
- Alert title
- Status - Open, In Progress, Closed
- Disposition - Benign, Malicious, Undecided, Not Applicable
- Severity
- Assignee
- Source
- Created and Last Updated timestamps
- AI Determination - the AI agent’s conclusion and confidence level (for autonomously investigated Alerts)
- Tags
Tabs
The body of the Alert Details page is organized into tabs. The tabs available depend on whether the Agentic SOC agent investigated the Alert autonomously.
Tab availability by Alert type
Autonomously investigated Alerts (from Microsoft, CrowdStrike, or SentinelOne) display all tabs: AI Investigation overview, Playbook, Evidence, Timeline, Threat Intelligence, Related Activity, and Audit Log.
Alerts from all other integrations display Evidence, Timeline, Threat Intelligence, Related Activity, and Audit Log. These Alerts don’t show the AI Investigation overview and Playbook tabs.
AI Investigation overview (autonomously investigated Alerts only)
The AI Investigation overview tab is your starting point for understanding an autonomously investigated Alert. It surfaces the AI agent’s high-level findings so you can quickly understand what happened and what action, if any, is needed.
This tab includes:
- Investigation Summary - A human-readable narrative that the AI agent generates, describing the activity, the entities involved, the evidence reviewed, and the conclusion reached.
- AI Determination - The AI agent’s disposition recommendation (Benign, Malicious, or Undecided) and a confidence level. The AI agent may close the Alert automatically when the determination is conclusive.
- Recommended next steps - Actions the AI agent recommends based on its findings, such as reviewing a specific entity or running a containment action.
- Key entities - The users, assets, IP addresses, and other indicators of interest identified during the investigation. Click any entity to pivot to related data in Log Search or other product areas.
If a human analyst updates the disposition, the tab displays both the AI determination and the human determination, making clear which conclusion is the human’s and which is the AI’s.
Playbook (autonomously investigated Alerts only)
The Playbook tab displays the full investigation playbook that the Agentic SOC agent ran, including every question it asked, every data source it queried, and the result of each step. This tab makes the AI investigation fully transparent and auditable.
Each entry in the Playbook shows:
- Investigation question - The specific question the agent was trying to answer (for example, “Has this user authenticated from this IP address before?”).
- Query executed - The exact query the agent ran against the available telemetry.
- Result - The data returned and the agent’s interpretation of that result.
You can search the Playbook using the search bar at the top of the tab to find a specific query or result by keyword or entity name.
Evidence
The Evidence tab displays the raw data supporting the Alert, including the original Signals, the log payloads that triggered each detection, and any telemetry collected during investigation.
This tab includes:
- Original Signals - The list of Signals that make up this Alert, with links to each Signal’s detail view. Each Signal shows the detection rule that generated it, the severity, and the log payload.
- Raw log payload - The source log data in JSON format. View the payload as a formatted table or raw JSON. Click View Log Entry to open the associated log in Log Search with the relevant time range pre-selected.
- Matching keys - The specific fields in the log payload that matched the detection rule. Use the Highlight matching keys and Filter matching keys toggles to focus on the values that triggered the Alert.
- Telemetry data - For autonomously investigated Alerts, this section displays the raw telemetry fetched from the source integration during the AI investigation, including process logs, user activity logs, network activity, and other data pulled to support the playbook.
- Evidence links - Analysts and customers can add links to external evidence, such as a saved Log Search, a threat intelligence blog post, or a Jira ticket.
- Attachments - Analysts can upload supporting files (CSV, PDF, PNG, ZIP) and attach them to the Alert as evidence.
Timeline
The Timeline tab presents a single chronological narrative of the Alert, blending raw telemetry events, AI agent actions, and human analyst actions into one unified view.
The Timeline answers: “What happened, in what order, and who did what?” It’s especially useful for understanding attack progression and for shift handoff, letting a new analyst immediately understand the state of the investigation.
Timeline entries include:
- Detection events - Each Signal and the timestamp of the underlying activity.
- AI agent actions - Steps the AI agent took, such as running a query, fetching telemetry, or updating the disposition.
- Analyst actions - Comments added, status changes, disposition changes, assignments, and response actions taken by human analysts or customers.
- System events - Automated actions such as notifications sent, automated rules triggered, or bidirectional status syncs with external tools.
Threat Intelligence
The Threat Intelligence tab surfaces threat intelligence context related to the indicators of compromise (IOCs) found in this Alert, including IP addresses, file hashes, domains, and URLs identified in the Signals or during the AI investigation.
For each IOC, this tab shows:
- Threat classification - Whether the indicator is associated with known malicious activity.
- Confidence and severity - The confidence level and severity of the threat intelligence match.
- Associated threat actors or campaigns - Known threat actors or campaigns linked to the indicator.
- Source - The threat intelligence provider that supplied the data.
Related Activity
The Related Activity tab shows other Alerts and Signals in your environment that share contextual relevance with the current Alert, for example, Alerts involving the same user, asset, IP address, or similar detection patterns.
This tab helps you:
- Identify broader campaigns - See if the same actor or technique appears across multiple Alerts.
- Spot repeated activity - Quickly identify if this type of event has occurred before.
- Connect related investigations - Navigate to related Alerts to understand the full scope of an incident.
The system surfaces related Alerts automatically based on entity overlap between them.
Audit Log
The Audit Log tab provides a complete, chronological record of every action taken on this Alert, by any user, analyst, or automated system, since the Alert was created.
Each audit log entry records:
- Action taken - What changed (for example, status updated, disposition changed, comment added, AI investigation completed).
- Actor - Who or what made the change: a named analyst, a customer user, the Agentic SOC AI agent, or an automated rule.
- Timestamp - When the action occurred.
The Audit Log is append-only. You can’t modify or delete entries. You can filter the log by actor type, action type, or time range. To query the Alert audit log in Log Search, go to Log Search and select the Audit Logs log set with the SIEM (InsightIDR) Alerts log.
Ask AI
The Ask AI panel is a conversational AI assistant scoped to the current Alert’s investigation context. Type a question in natural language to get a context-aware response, for example, asking about a specific entity, querying whether similar behavior has occurred before, or requesting a plain-language explanation of part of the investigation.
Ask AI is informational only. It doesn’t take actions on your behalf. It can’t update Alert attributes, run queries, or trigger response actions. All actions remain under analyst control. To open Ask AI, click the Ask AI button on the Alert Details page.
Response actions
For supported integrations, you can run containment and response actions directly from the Alert Details page without leaving the investigation context. Available actions depend on the integration sources associated with the Alert:
- CrowdStrike Falcon - Quarantine host, Unquarantine host.
- SentinelOne - Quarantine host, Unquarantine host.
- Microsoft (Entra) - Suspend user, Unsuspend user.
- Microsoft Defender for Endpoint - Quarantine host, Unquarantine host.
The system logs response actions in the Audit Log and displays them in the Timeline. Only privileged users and MDR analysts with appropriate permissions can run response actions.
Comments and collaboration
All users, both MDR analysts and customer users, can add comments to an Alert from the Alert Details page. Comments are visible to all parties with access to the Alert and are recorded in the Audit Log.
MDR analysts can also add internal comments that are visible only to the MDR team; customer users can’t see internal comments.
When a customer adds a comment, they can optionally notify the assigned MDR analyst by toggling the notification option before submitting.
Requests for Information (RFIs)
From the Alert Details page, you can access and manage RFIs related to this Alert:
- Inbound RFIs - View and respond to RFIs your MDR team submits requesting additional context from your organization.
- Outbound RFIs (MDR analysts only) - Submit an RFI to the customer requesting specific information needed to complete the investigation.
The in-product RFI hub is accessible from the Alert Details page and shows all RFIs associated with the current Alert.