This page describes the security alerts that you can set up on Cisco Secure Application. 

Navigate to Alerts

On the Cisco Secure Application > Alerts page, you can view these details: 

  • Severity: These are the three statuses for a severity: Normal, Warning, Critical. 

  • Status: The status of the database provider, which is either active or inactive. 
  • Category: The category of the alert: Exfiltration, Compliance, Best Practices, Suspicious Activity, Unused Privileges, or Over Provisioning. 

  • Start Time: The time of the alert. 
  • Affected Entity: The name of the entity that is affected. 
  • Description: A description of the alert. 

Overview UI Screenshot

When you click on the name of a specific alert, you can view these details: 

  • Alerts Overview 
  • Confidence Score 
  • Event Timeline 
  • Data Flow Map 
  • Data Export Activity 
  • Alert Details

Overview UI Screenshot