Skip to main content
User guide

Posture

First screen after login: alerts in the window, critical + high, baseline failures, platform issues; the ten noisiest rules and ten latest alerts.

Posture generates nothing; it gathers numbers from Live alerts, Baseline, Platform health and Analysis records, refreshing every 30 seconds (pausable). Every edition.

Posture

Key figures

Key figures

CardSourceClick goes to
AlertsAlerts ingested in the windowLive alerts
Critical + highSame, critical and high only; badge "look first" when > 0Live alerts, filtered
Baseline failuresFailed checks in the latest run; "never run" before the firstBaseline
Platform issuesNon-passing checks in the latest check-upPlatform health

The window is the time picker top right, 24 hours by default.

Timeline and severity mix

Timeline

Stacked per hour (per day for wide windows) by severity; next to it the severity share of the window.

Noisiest rules / latest alerts

Two top-10s

  • Noisiest rules top 10: "View" jumps to Live alerts filtered on that rule. One noisy rule is often most of the queue; start here.
  • Latest alerts top 10: severity / rule / subject / time, with a search box; "Handle" opens the feed.

Archive

The bottom line shows how many investigations and triages are archived, linking to Analysis records.

The four small cards on the Smart query home (open alerts, baseline failures, platform issues, records) are a compact version of this page.

On this page