Skip to main content
User guide

Investigations

Automatic archive of problem investigations and alert correlations, kept per account, with follow-up questions about a device and pushing a finding to notification channels. All editions.

Investigations archives two kinds of AI analysis automatically and is available in every edition. A record is created when a problem investigation finishes and when an Alert correlation run finishes. You do not save anything by hand.

Records are kept per account; each account sees only the analyses it started. They are stored on the gateway and removed after RST_ANALYSIS_TTL_DAYS (30 days by default).

Investigations

Find a record

Steps

  1. At the top, pick a type: All, Investigation or Correlation.
  2. (Optional) Type a keyword in Search titles, summaries and devices….
  3. The list loads 30 records at a time; select Load more for older ones.

Ask a follow-up question

Steps

  1. Select a record to open its details.
  2. Select Ask about this device.

The device goes to Ask AI as a new question: what problems it has had in the last 24 hours.

Record details

Push an investigation finding

An investigation record has Push in its details. It sends the finding to the Outbound channels whose severity threshold the finding meets.

Prerequisites

  • A Professional or Enterprise license, including a trial.
  • Analyst or administrator role.
  • At least one channel set up under Outbound channels.

Steps

  1. Open an investigation record.
  2. Select Push.

On success you see how many channels it went to. If no channel meets the severity threshold, nothing is sent and you are told so.

What a record holds

TypeContent
InvestigationThe full problem investigation: conclusion, false-positive verdict, timeline, impact chain, affected objects, recommended actions, lookup steps
CorrelationThat run's alert storms, root-cause devices, groups, severities and recommendations

On this page