How to create an Alert Queue

800800
  1. Head over to Alerts > Workflows.
  2. Open the Queues tab:

🚧

I can't see the Queues tab!

If you cannot see the queues tab, you do not have the necessary permissions.

53445344

Here you will see a list of all the alert queues that currently exist.

  1. Press the + Create A New Queue button. A prompt will appear:
53445344
  1. Fill in the required information:
53445344

Queue Name

The only non-optional item is the name.

Description

This is optional. Please use a description that your agents will understand.

Rules

Here you can choose the rule in which the alerts created by said rule will filter into your new alert queue. This is optional but must be filled in later if omitted during queue creation (fill it in during rule creation).
Route alerts to a queue using the rule's logic (or by manually assigning it after the alert is generated).

❗️

ONLY 1 RULE CAN BE ASSOCIATED WITH A QUEUE.

If rule is already associated with another queue, it will get disassociated from that queue immediately.

Team

Here you can choose which team or teams can read alerts in this new queue.
Only agents who are assigned to a queue can investigate its alerts.

Order in which alerts are consumed from this queue

There are three ways to designate the order in which alerts are investigated:

If you select...then agents will
Oldest Creation Dateinvestigate in the order the alerts were created
Highest Transaction Valueinvestigate starting with the alert whose events have the highest transaction sum
Highest Risk Scoreinvestigate starting with the entity that has the highest risk score
  1. Click Create Queue.

Your new alert queue has been created.

Permissions required for Alert Queue Creation:

  • To fully work with alert queues, you need at least the following permissions:
    • create/edit rules
    • create/edit alert queues
    • reassign queues
    • create/edit alerts

Did this page help you?