Alerts
What is an Alert?
Limited Availability
Agentic SOC is available to a limited set of US-based customers as part of a Limited Availability release. If you don’t see the Signals or Alerts pages described in this documentation, your organization hasn’t yet been migrated to Agentic SOC. Your existing Alerts and Investigations experience remains unchanged until migration.
Alert terminology has changed
In previous versions of SIEM (InsightIDR), Alerts referred to individual detection events. With Agentic SOC enabled, Alerts now represent clusters of one or more related Signals, and individual detection events are called Signals. See Signals for more information.
An Alert is the primary unit of investigation work in SIEM (InsightIDR) when Agentic SOC is enabled. Each Alert represents a cluster of one or more related Signals that the AI clustering engine has determined belong to the same security incident or investigation unit.
Alerts are where triage, investigation, and response actions take place. Whether the AI agent investigated an Alert autonomously or assigned it to your MDR team for manual review, the Alert is the single place where all context, evidence, decisions, and actions are captured.
How Alerts are created
The AI clustering engine automatically creates Alerts by grouping related Signals. This is the most common source of Alerts. The engine clusters every Signal generated for your organization into an Alert.
Email notifications for Signals have changed
Once your organization is migrated to Agentic SOC, email notifications for individual Signals are disabled. Email notifications are sent for Alerts instead, for example, when a new Alert is created and when an Alert is updated. You can configure email notification preferences from the Notifications settings page.
Alert attributes
Each Alert carries the following attributes, which you can view and, where permitted, update from the Alerts page or the Alert Details page:
- Title - A system-generated name derived from the detection rules in the cluster, or a custom name if created manually.
- Status - The current workflow state of the Alert. Values: Open, In Progress, Closed.
- Disposition - The conclusion reached about the Alert. Values: Benign, Malicious, Undecided, Not Applicable.
- Severity - The assessed severity of the Alert. Values: Informational, Low, Medium, High, Critical.
- Source - The primary integration or event source associated with the Alert.
- Assignee - The analyst or team member currently responsible for the Alert.
- Signals - The number of Signals grouped into this Alert.
- Created - The timestamp of the first Signal in the cluster.
- Last Updated - The timestamp and actor of the most recent change to the Alert.
- AI Determination - The Agentic SOC agent’s conclusion and confidence level (for autonomously investigated Alerts).
- Tags - Custom labels that analysts can apply for categorization and filtering.
Who can update an Alert
Update permissions depend on whether the Alert is MDR-managed or customer-managed:
- MDR-managed Alerts - Only MDR analysts can update the disposition, status, severity, and assignee on Alerts that are the responsibility of the Rapid7 MDR team. Customers can add comments and view all investigation data.
- Customer-managed Alerts - Any privileged user in your organization can update the disposition, status, and other attributes.
Human decisions are preserved
If an analyst manually updates the status or disposition of an Alert, the AI agent doesn’t overwrite that change, even if new Signals are added to the cluster and a re-investigation is triggered. Human decisions always take precedence over automated updates.
View the Alerts page
From the left navigation menu, select Alerts. The Alerts page displays your Alert queue, all current Alerts for your organization, ordered by creation time by default.
Alert table
Each row in the Alerts table represents one Alert. You can expand rows to show the individual Signals that make up that Alert; rows are collapsed by default.
Selecting a row opens the Alert side panel, which shows a quick summary of the Alert, including key entities, the AI determination (if applicable), investigation summary, related Signals, and related Alerts. From the side panel, you can update the Alert’s status and other attributes without leaving the queue.
Time series
A severity-coded time series chart above the table shows Alert creation volume over time, giving you a quick view of activity spikes and workload patterns. You can collapse the time series if you prefer a larger table view.
Search for Alerts
To narrow your view of Alerts, apply filters using the search bar at the top of the Alerts page. You can combine multiple filters and group the results by any Alert attribute.
Available filters:
- Time Range - Filter for Alerts created within a specific time period.
- Status - Filter by Open, In Progress, or Closed.
- Disposition - Filter by Benign, Malicious, Undecided, or Not Applicable.
- Severity - Filter by Informational, Low, Medium, High, or Critical.
- Source - Filter by the event source or integration.
- Assignee - Filter by the analyst the Alert is assigned to.
- AI Determination - Filter by the AI agent’s determination for autonomously investigated Alerts.
- Tags - Filter by custom tags applied to Alerts.
- Responsibility - Filter by MDR-managed or customer-managed Alerts.
- Customer (MDR analysts only) - Filter by customer organization name.
Customize the table
You can customize which columns display in the Alert table to surface the fields most relevant to your workflow. Click Edit Table to open the column editor, select the fields you want to display, and drag them into the order you prefer.
Save views
After applying filters, queries, and column selections, you can save your view for later. Click Workspace Actions > Save to create a named workspace. You can share saved workspaces with other users by copying the workspace configuration as a JSON string and importing it into another account.
Bulk actions
You can update multiple Alerts at once by selecting checkboxes in the table and choosing a bulk action. Bulk actions can change these attributes:
- Status
- Disposition
- Assignee
- Severity
- Tags
- Closure reason
- Comments
Bulk actions open a confirmation modal where you can add a comment that applies to all selected Alerts.
Email notifications
SIEM (InsightIDR) can send email notifications for Alert activity. Notifications are available for:
- New Alert created - Sent when your organization creates a new Alert.
- Alert updated - Sent when an Alert’s status or other key attributes change.
You can enable or disable email notifications from the Notifications settings page. You can toggle individual notification types independently.
Add an Alert to an Investigation
You can add Alerts to an Investigation, either to an existing Investigation or to a new one created from the Alert. To do this, open the Alert Details page and select Add to Investigation from the Alert actions menu.
This workflow bridges the new Alert experience and the existing Investigation workflow. Investigations remain useful for escalation, formal customer communication, and cases that require longer-duration collaborative tracking across multiple parties.
During the transition period, day-to-day triage and investigation work is expected to move to Alerts. Use Investigations as the escalation layer for situations that need formal customer-facing documentation, multi-team coordination, or tracking beyond a single investigation unit.