---
title: "See triggered alerts' details"
canonical: "https://docs.devo.com/space/latest/528351678/See%20triggered%20alerts'%20details"
format: markdown
---
> Macro (toc)

## What permissions do I need?

To access the Alerts overview area and see the alert details, you need at least the *Triggered alerts (view)* and the *Read/unread alert* permissions (see a detailed description of the alert permissions [here](https://devodocs.atlassian.net/wiki/spaces/latest/pages/530153550)).

Additionally, you need to have alerts assigned with *View* access (see [Assign resources to a role](https://devodocs.atlassian.net/wiki/spaces/latest/pages/94763463)), which will be those you will see on the list.

## Checking alert info

You can see the *Summary* and *Description* of a triggered alert by clicking the expandable arrow next to the alert name. Here you can also find the alert *Extradata* for quick access, which is especially useful when [filtering by Extradata](https://docs.devo.com/space/latest/405700704/Filter+triggered+alerts#Filter-by-Extradata). Expanding the alert details will automatically mark it as watched (visit [this article](https://devodocs.atlassian.net/wiki/spaces/latest/pages/528973959) to know more about the status). *Entity attributes* space shows all the [attributes extracted from the alert query](https://docs.devo.com/space/latest/1065844743/Using+entities+attributes+in+triggered+Alerts) to correlate and offer more context to your investigations.

Expanding the alert details will automatically mark it as a watched [status](https://docs.devo.com/space/latest/525860890/Navigate+triggered+alerts).

If any of the fields cannot be seen completely on the list, you can click on it to show a floating window with the complete info.

![10_ See triggered alerts update (1).png](media://6bfc83e7-7105-4150-9620-91104b4930b6)

For child domains in multitenant structures, users will additionally visualize the [owner domain for those shared alerts](https://devodocs.atlassian.net/wiki/spaces/latest/pages/1333526603/Sharing+alerts+between+domains#Viewing-alerts), which differs from those in the own domain.

## Checking alert details

To see the complete information of a triggered alert in the details window, you can either click an alert’s ID on the list or use the [Search by ID](https://docs.devo.com/space/latest/405700704/Filter+triggered+alerts#Search-triggered-alerts-by-ID) functionality.

![15_See triggered alerts' details.png](media://5bc44914-9e55-4527-b186-7b6857630d6c)

By right-clicking on the alert's ID, you can choose the option to open it in a new tab, or use the keyboard shortcut: **Ctrl + T** (Windows & Linux) or **⌘ + T** (Mac).

### Visualization in the details window

Once you open this window, the alert status is automatically updated to *watched*, and you have access to the following pieces of information (see numbers in light blue on the picture below for reference):

1. Name, category-subcategory, date triggered, ID, priority, and status.

- Inside this area, you can find a back arrow to return to the alert list.
- There is a copy button next to the ID for later use in searches (see [search alert by ID](https://docs.devo.com/space/latest/405700704/Filter+triggered+alerts#Search-triggered-alerts-by-ID)).
- You can check status and priority here, as well as manage them (see section below).

2. Summary, description, owner, query timezone, and type ([triggering method](https://docs.devo.com/space/latest/95126609/Alert+definitions+settings#Trigger-methods-explained) and its specific settings).

- This is how the alert definition was configured when [created](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126538) or [edited](https://devodocs.atlassian.net/wiki/spaces/latest/pages/529039378).

3. Entity attributes.

- You can review the attributes mapped with your alert at the creation moment, the tags indicate the name of the attribute, the value, and whether the attribute works as source () or as a destination () of the action or event[.](https://docs.devo.com/space/latest/424542253/Devo+Cyber+Data+Model+(DCDM))

4. Query and Extradata.

> Macro (excerpt)
> 
> If the query used in the alert rule has been edited, the query expression is applied retroactively to triggered alerts but the triggered alert contents are not updated.

- You can further explore the query to analyze the events that triggered the alert by clicking the **Open in query editor** button. This is the same as the **Go to query** option you can find on the alert list (visit [Explore triggered alerts’ query](https://devodocs.atlassian.net/wiki/spaces/latest/pages/529858671) for more info).  
There is a copy button inside the query block so you can use it elsewhere.
- You can adapt the *Extradata* to show the raw configuration or the decoded version (more info about the extraData [here](https://devodocs.atlassian.net/wiki/spaces/latest/pages/576552961)). Simply click the switch above the *Extradata* field. This is useful when you work with JSON.

> ⚠️ **Dates in Extradata**
> ⚠️ 
> ⚠️ Note that dates (e.g., event date, creation date) are displayed in UTC in the raw configuration but in the user’s timezone in the decoded version.

![See triggered alerts' details (1).png](media://c11035ca-9424-4d9c-91d6-3cb144cae071)

### Management tasks in the details window

In this window, you can also perform management actions such as (see numbers in dark blue on the picture below for reference):

1. Change **status** and **priority**: use the drop-down menus below the alert name at the top (more info here: [status](https://devodocs.atlassian.net/wiki/spaces/latest/pages/528973959), [priority](https://devodocs.atlassian.net/wiki/spaces/latest/pages/529105042)).
2. Post filters, alert definition, and triggered alert:

- Create and edit **post filters**: use the post filter button at the top right (more info here: [post filters](https://devodocs.atlassian.net/wiki/spaces/latest/pages/405701006)).
- Edit and clone **alert definition**: use the ellipsis button at the top right, next to the post filter button (more info here: [edit and clone](https://devodocs.atlassian.net/wiki/spaces/latest/pages/529203340)).
- **Delete** triggered alert: use the ellipsis button at the top right (more info here: [delete](https://devodocs.atlassian.net/wiki/spaces/latest/pages/529891502)).

3. Leave **comments**: use the *Comments* tab to see existing comments and write your own (more info here: [comments](https://devodocs.atlassian.net/wiki/spaces/latest/pages/405700954)).

![See triggered alerts' details (2).png](media://2e1e2c5f-a2d9-4d34-8be4-091874db2743)