Analyze Alerts on the Alerts Dashboard

You can view and analyze auditing-based alerts from the Alerts dashboard.

About the Alerts Dashboard

By default, the Alerts dashboard shows you a summary of alert activity for the last seven days, for all target databases, in the form of charts and tables. You can filter the alerts as needed. The charts and tables are updated based on the filters that you set.

  • The Alerts summary chart helps you to see the severity of the alerts quickly by comparing the percentage of critical, high, and medium risk alerts.
  • The Open Alerts chart helps you to see the trend of open alerts by showing you the number of open alerts for the last seven days.
  • The Alerts summary tab shows you a table consisting of the number of target databases and alerts at each alert severity level (Critical, High, and Medium). It also shows totals for all alerts.
  • The Targets Summary tab shows you a table consisting of alert totals for each target database. You can view the number of open alerts and the number of critical, high, and medium risk alerts.

View and Filter the Alerts Dashboard

You may want to filter the data summarized on the Alerts dashboard. You can filter by compartment, time period, and/or target databases.

  1. Under Security Center, click Alerts.
    The Alerts dashboard is displayed.
  2. From the Compartment drop-down list, select the compartment that contains the target databases for which you want to view alert summaries. Optionally, you can select Include child compartments.
  3. From the Time Period drop-down list, select the time period for the alert activity.
    You can select Last 24 Hours, Last 1 Week, Last 1 Month, Last 3 Months, Last 6 Months, or Date Range. If you select Date Range, specify the beginning (Time From Month) and end (Time To Month) months.
  4. From the Target Databases drop-down list, select a specific target database or All.
    Only target databases that are contained in the compartment (and child compartments if you selected the option) are listed. If you select All, then data for all target databases in the selected compartment is included in the dashboard.
    As you enter the name of a target database, the list of target databases gets filtered.
  5. View the Alerts summary chart and Open Alerts chart.
  6. View the Alerts Summary and Targets Summary tabs.

Analyze Alert Data

  1. Under Security Center, click Alerts.
    The Alerts dashboard is displayed.
  2. Filter the alerts as needed.
  3. To view all the alerts based on a severity level, on the Alerts summary tab, click an alert severity link (Critical, High, Medium, or All Alerts).
    The relevant alerts are displayed.
  4. To view all the alerts based on a target database, click the Targets Summary tab, and then click a target database name.
  5. At the top of the page, view the filters that are currently applied to the list of alerts.
    These filters are the same as those that were applied to the dashboard.
    You can modify, remove, and add filters as needed.
    Filter types include Created on, Updated, Alert Type, Alert Status, Alert Severity, Operation, Operation Time, Operation Status, and Target Name.
  6. View the summary totals based on the filters set.
    There are totals for the total number of targets, the number of open, critical, high, medium, and low risk alerts; the total number of alerts, and the number of closed alerts.
  7. To view the target database names, click Targets.
    A Targets dialog box is displayed listing the target database names. Click Close to close the dialog box.
  8. To filter the data in the table below the summary totals, click on any of the other summary totals. For example, to view only critical alerts in the table, click the Critical total.
    The table is automatically filtered.
  9. In the table at the bottom of the page, view the list of alerts.
  10. To add and remove columns from the alert list, from the Actions menu, select Manage Columns. The Manage Columns screen is displayed. Select/deselect columns, and then click Save Changes.The following columns are available:
    • Alert Name (displayed by default)
    • Alert Status (displayed by default)
    • Alert Severity (displayed by default)
    • Target Databases (displayed by default)
    • Created On (displayed by default)
    • Alert Policy
    • Operation
    • Operation Status
    • Operation Time
    • Alert Id