Skip to content

Alerts

Alerts are generated when SilentPulse detects silence or degradation in your security pipeline.

Generated when an asset stops reporting expected telemetry.

CRITICAL: 15 Windows servers silent for EDR telemetry
Last seen: 4 hours ago
Affected assets: SRV-001, SRV-002, ...

Generated when reporting frequency drops below expected levels.

WARNING: EDR telemetry degraded by 40%
Expected: 1000 events/hour
Actual: 600 events/hour

Generated when SilentPulse cannot reach an external system.

ERROR: Unable to connect to Splunk
Last successful query: 30 minutes ago
SeverityDescription
InfoInformational, no action required
WarningPotential issue, investigate soon
CriticalVisibility gap, immediate action required
ErrorSystem error, integration failure
  1. Open - Alert triggered, awaiting action
  2. Acknowledged - Someone is investigating
  3. Resolved - Issue fixed, telemetry restored
  4. Closed - Manually closed (false positive, expected)

Configure where alerts are sent:

  • Email - Individual or group addresses
  • Slack - Channel or DM notifications
  • Webhook - Custom integrations
  • PagerDuty - Incident management
  • Microsoft Teams - Channel notifications

From the alert detail page:

  • Acknowledge - Mark as being investigated
  • Snooze - Suppress for a time period
  • Create Ticket - Open issue in Jira/ServiceNow
  • View Timeline - See historical context
  • Run Playbook - Execute remediation steps