MODULES / Alerts

Signal, not noise

Alerts

Filter critical and high-severity threat signals from your log stream by priority. Details on the Alerts module's rule engine and filters.

  • PRIORITIZATION
  • ESCALATION
  • NOTIFICATION

[ PURPOSE & VALUE ]

What does Alerts do?

A SOC analyst's most valuable resource is time. Missing a genuinely critical threat buried among thousands of medium- and low-severity logs every day can be disastrous. The Alerts module lists every warning generated by NextPcap's rule engine, prioritized by severity (Critical, High, Medium, Low). An advanced filtering panel lets you instantly narrow results to a specific server, IP, or rule name.

[ FEATURES ]

What Alerts delivers

Actionable Alert Cards

The triggering rule name, the affected server, the attacker's IP, and the raw log content can all be reviewed on a single screen.

Status Management

Security analysts mark alerts they're reviewing as 'Acknowledged,' preventing duplicate work across teams.

Advanced Filtering Interface

Multi-criteria search filters by date range, alert severity, server name, and IP.

[ HOW IT WORKS ]

Live in three steps

Filter

Raw events are filtered by risk and recurrence.

Rank

Critical alerts are moved to the top.

Notify

Delivered instantly to the responsible team via the set channel.

[ RELATED MODULES ]

Works together with Alerts

[ FAQ ]

Frequently asked questions about Alerts

How does the Alerts module surface critical warnings?

Every alert is prioritized as Critical, High, Medium, or Low, with critical alerts always appearing at the top of the list.

Can the same alert be reviewed redundantly by multiple analysts?

No — the 'Acknowledged' status lets teammates see that an analyst has already taken ownership, preventing duplicate work.

See Alerts live

Headquarters: Ankara · iletisim@nextpacketcapture.com