Helix automatically groups alerts from all sources for a given rule ID that share the same groupby value in the rule definition. This can help you identify patterns across your environment, and lets you quickly take action against all alerts in the same group. To switch between all alerts and grouped alerts, use the Correlated Alerts toggle. The Correlating Attributes column shows the attributes that link the grouped alerts.
Tip
You can also add this column to the standard view of the alerts table, select Settings
> Customize Columns > Correlating Attributes.
When you click on an alert row, a side panel opens with more information about the alert. If you select a parent alert, the side panel also includes information about any child alerts. If you select a child alert, the side panel only shows information about that child alert.
If you perform an action on a parent alert from the alerts table, the action will also apply to the child alert. For example, if you click More Options (
) at the end of the row of the parent alert and assign this parent alert to an analyst, all child alerts will also be assigned to the analyst. However, if you click an alert name and assign the alert from here, the action will only apply to that alert.