Skip to main content

How to manage alert scenarios

View and configure the scenarios that drive Sentinel alert generation.

H
Written by Harriet Christie

Summary

Scenarios are the rules that cause messages to be flagged as Sentinel alerts. Scenarios are organised within scenario categories. From a category's detail page you can see each scenario, read its description, see how many alerts it has produced, and open its alerts. Editing an individual scenario's settings is available only when scenario editing is enabled for your organisation.

The UI does not provide a way to create or delete scenarios. You view the scenarios that exist within each category and, where editing is enabled, adjust an individual scenario's settings.

Prerequisites

  • Login credentials to MirrorWeb Insight

  • Access to an organisation that has Sentinel enabled

  • To open a scenario's settings, scenario editing must be enabled for your organisation

Step-by-Step Instructions

Step 1: Open the Scenarios area

In the sidebar, under Sentinel, select Scenarios to open the Scenario Categories page, then select a category to view its scenarios.

The Scenario Categories page

Step 2: View the scenarios in a category

The category detail page lists the category's scenarios under a "Scenarios" heading. Each scenario shows its name, a description, and an alert count badge (for example "0 alerts" or "12 alerts"). If a category has no scenarios, the page shows "No scenarios available for this category."

A category detail page listing scenarios with alert count badges

Step 3: View a scenario's alerts

For a scenario that has alerts, use the view-alerts action on the scenario row to open the Alerts page filtered to that scenario.

A scenario row with the view-alerts action

Step 4: Open a scenario's settings (if enabled)

If scenario editing is enabled for your organisation, an edit (cog) icon appears on each scenario row. Select it to open the scenario's Settings page. See How to configure scenario settings and rules.

A scenario row showing the edit (cog) icon

Notes

Note: Alert counts shown on a scenario indicate how many alerts that scenario has produced; selecting the count opens those alerts in the Alerts page.

Note: Some categories are only shown to specific organisations and may be hidden for yours.

Did this answer your question?