Security Events

One feed for compliance violations, real-time alerts, and behavioral anomalies.

Security detection

Security Events is a unified feed of three signal types: violations (control failures), alerts (real-time security events ingested from connectors), and anomalies (behavioral findings like role creep or dormant-admin activity). Each item has a severity (critical / high / medium / low) and a status you move through as you triage.

How to use it

  1. Open Security Events from the sidebar to see the combined feed.

  2. Filter by type (violation, alert, anomaly), severity, and status to focus on what matters now.

  3. Click into an item to see its details, the evidence behind it, and the affected identity or resource.

  4. Move an item through its status lifecycle — open, acknowledged, remediating, resolved, or dismissed — as you work it.

  5. Escalate items that need a tracked remediation plan into the Compliance Ops POAM workflow or into Investigations.

Tips

  • Start each day filtered to critical + high, open status, to triage the highest-impact items first.

Open Security Events in the app

Jump straight to the feature, or browse the rest of the guides.