The triggering rule name, the affected server, the attacker's IP, and the raw log content can all be reviewed on a single screen.
MODULES / Alerts
Signal, not noise
Alerts
Filter critical and high-severity threat signals from your log stream by priority. Details on the Alerts module's rule engine and filters.
- PRIORITIZATION
- ESCALATION
- NOTIFICATION
[ PURPOSE & VALUE ]
What does Alerts do?
A SOC analyst's most valuable resource is time. Missing a genuinely critical threat buried among thousands of medium- and low-severity logs every day can be disastrous. The Alerts module lists every warning generated by NextPcap's rule engine, prioritized by severity (Critical, High, Medium, Low). An advanced filtering panel lets you instantly narrow results to a specific server, IP, or rule name.
[ FEATURES ]
What Alerts delivers
Security analysts mark alerts they're reviewing as 'Acknowledged,' preventing duplicate work across teams.
Multi-criteria search filters by date range, alert severity, server name, and IP.
[ HOW IT WORKS ]
Live in three steps
Raw events are filtered by risk and recurrence.
Critical alerts are moved to the top.
Delivered instantly to the responsible team via the set channel.
[ RELATED MODULES ]
Works together with Alerts
[ FAQ ]
Frequently asked questions about Alerts
Every alert is prioritized as Critical, High, Medium, or Low, with critical alerts always appearing at the top of the list.
No — the 'Acknowledged' status lets teammates see that an analyst has already taken ownership, preventing duplicate work.
See Alerts live
Headquarters: Ankara · iletisim@nextpacketcapture.com