Alert rules
Rules define which threats should emit alerts. Each rule can include:enabledtitleseverity_thresholdasset_idsthreat_typesmax_distance_kmmute_interval_hours- delivery toggles such as
email_enabled,sms_enabled, andslack_enabled
Triggered alerts
Triggered alerts are persisted rows with their own lifecycle state. Important fields include:- alert ID
- related
threat_id - alert type
- severity
- state
- matched rule ID and title
- distance bounds
- created/updated timestamps
Alert states
Triggered alerts move through these states:newseenackeddismissed