Skip to main content

Security Alerts

Security Alerts lists what the detectors raised in the workspace over the time range: the totals by severity, the top alert types, the severity trend, and the alerts themselves.

The Security Alerts page for the Production workspace

Narrowing the list​

Hover a column header for its filter; the timestamp header sorts. Filters apply to the cards at the top as well as the table.

The severity filter and the timestamp sort

The severity filter open

The Alert Types Reference explains every type in the Type column, and what each severity means.

Opening an alert​

Click a row to open the alert.

A row of the alert list, highlighted

Alert details​

The side panel identifies the alert: severity, when and where it was detected, the GPU involved, and its MITRE ATT&CK® mapping. The tabs beside it tell the story.

The three alert details tabs

Timeline — What happened in plain language, then the process-level events leading up to the alert.

The Timeline tab for a cross-tenant GPU memory access

Resource Details — the process, memory, node and GPU as they were at the moment of the alert.

The Resource Details tab

Connectivity — the host's NVLink neighbourhood at the time of the alert: the other GPUs on the node, the switches between them, and which of them carry alerts of their own.

The Connectivity tab

Reports and actions​

Download Report produces a printable report of the alert; the panel's download icon exports its fields as CSV.

The Download Report button and the export icon

When the alert names a GPU, Take Action offers the same isolate and reset commands as the Compute Index.

The Take Action button on an alert

Back returns to the list, on the same workspace and time range you came from.

The Back button

Going deeper​

  • Every alert on this page is an API call away: GET /alerts takes the same filters, and the examples page through them and build severity breakdowns.
  • Ask an assistant to triage instead: the MCP server lists, reads and summarizes alerts; see Tools and the triage examples.
  • Send alerts to the SIEM your SOC already watches: see Integrating with Your Environment and the SIEM export tab.