Monitoring situations


The Situations page displays all policy-based or ML-based situations identified from the events.

As an operator, you can use the Situations page to monitor ML-based or policy-based situations. Each situation is represented as a tile in the view and can be investigated individually to perform additional actions.

To monitor Situations

  1. Click Situations to view the following details:
    • Situation name: Click to view Situation details. 
    • Time when the Situation occurred
    • Related events: Click to view event details in the Situation details page. 
    • Type: Icon to indicate whether it is an ML-based or policy-based Situation (requires configuration)
    • Severity: Color-coded 
    • Priority: Color-coded
    • Status: Open or closed
    • Incident ID (if available)
    • Available automations (requires configuration)
    • Actions: Available to perform for a Situation

      Situations.png
  2. (Optional) To choose how to view Situations in both tile view or list view, use the following information:

    Additional options to view Situations
    • Time period: Use the date and time filter to view Situations for a selected period. By default, Situations for the last 24 hours are displayed. 
    • Basic search: Enter a Situation name (case-sensitive) in the search box and click search.png.
    • Advanced filter to view Situations: Use the filter to view Situations based on the status, severity, priority, and type. 
      By default, open Situations of the severities Critical, Major, Minor, Warning, and Information for the last 24 hours are displayed.
    • Sort: Sorting is available for the Occurred, Severity, Priority, and Status columns.
    • Column selector: Click Column Selector Button.pngto clear the columns that you do not want to appear in the list view. Only selected columns appear on the Situations page.  
    • Refresh page: Click Refresh.png (Refresh) to refresh the page. 
  3. (Optional) To view Situations in a tile view, click Tile View Button.png(Tile View). 
    Displays all Situations in a tile view with the following details on each tile:
    • Situation name
    • Time passed since the Situation occurred, or date and time of the Situation
    • Severity: Color-coded 
    • Priority: Color-coded
    • Type: Icon to indicate whether it is an ML-based or policy-based situation
    • Total number of events in a Situation
    • Status

      Note

      Search results or filters are retained across the list view and the tile view. 

      Situation Tile View.png


Where to go from here

Click a policy-based or an ML-based situation tile to investigate and remediate the situation: 

 

Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*