---
title: "Alerts monitoring"
canonical: "https://docs.devo.com/space/latest/95206409/Alerts%20monitoring"
format: markdown
---
The following tables can help you monitor different aspects of the existing alerts in the web application. This may be useful in case you want to have a general overview of the alerts in the system, check their parameters, or spot potential errors.

> Macro (toc)

> Macro (anchor)



## `siem.logtrust.alert.info`

<span style="color: #172b4d">In this table, you can find detailed information about all alerts triggered in the current domain. You can see below the most relevant fields included in this table along with a brief explanation.</span>

Use an [alert definition](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126538) to create triggered alerts.  Sending data to this table will not add items to the [triggered alerts](https://devodocs.atlassian.net/wiki/spaces/latest/pages/405700609) interface.

| **Field** | **Data type** | **Description** |
| --- | --- | --- |
| *alertHost* | `str` | [Internal field:] this field indicates an internal Devo component related to alert dispatching. |
| client | `str` | This field is hidden by default.  In a reseller, if [alert sharing](https://devodocs.atlassian.net/wiki/spaces/latest/pages/1333526603) is enabled, the *client* is the child and the *domain* is the root where the alert is configured.  If sharing is not enabled, *client* and *domain* are the domain where the alert is configured. |
| *domain* | `str` | Devo domain to which the alert belongs. |
| *priority*> Macro (anchor) | `float` | Priority level assigned to the alert, represented as a numerical value:<br>- *Very low - *`0`, `1`
- *Low - *`2`, `3`
- *Medium - *`4`, `5`
- *High - *`6`, `7`
- *Very high - *`8`, `9`, `10`<br>> ⚠️ **Devo alert priorities VS SecOps alert priorities**
> ⚠️ 
> ⚠️ Please keep in mind that these priority levels do not correspond to the ones used in the [Security Operations application](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95209242). |
| *context* | `str` | Contextualization of the alert resulting from a combination of its category, domain and name.<br>> ℹ️ **Special characters in the alert name**
> ℹ️ 
> ℹ️ Alert names are normalized upon creation, replacing all special characters (not alphanumeric) by underscores (_). |
| *category* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *alertId* | `str` | Unique ID assigned to the alert when triggered. |
| *status* | `int` | Condition of the triggered alert regarding their life cycle, represented as a numerical value:<br>- Unread → 0
- Updated → 1
- Watched → 100
- False positive → 2
- Closed → 300
- Suppressed → 800 |
| *srcIp* | `ip4` | [Deprecated field:] information is not provided in this field anymore. |
| *srcPort* | `int` | [Deprecated field:] information is not provided in this field anymore. |
| *srcHost* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *dstIp* | `ip4` | [Deprecated field:] information is not provided in this field anymore. |
| *dstPort* | `int` | [Deprecated field:] information is not provided in this field anymore. |
| *dstHost* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *protocol* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *username* | `str` | User who created the alert definition. |
| *application* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *engine* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *extraData* | `str` | Information extracted from different fields to indicate the conditions that triggered the alert (more info [here](https://devodocs.atlassian.net/wiki/spaces/latest/pages/576552961)). |
| *AlertContextSubscription* | `int` | [Deprecated field:] information is not provided in this field anymore. |
| *Alertcreationdate* | `timestamp` | Exact date on which the specified alert conditions were met and the alert triggered, which may reveal a slight delay with the eventdate (date on which the event was registered in the Devo table). |

> Macro (anchor)



## `siem.logtrust.alert.error`

<span style="color: #172b4d">In this table, you can find detailed information about all the alert errors that occurred in the current domain, understanding an error as an event in which the conditions have been met but the alert has not been triggered. It is very similar to the </span>[siem.logtrust.alert.info](/wiki/pages/resumedraft.action?draftId=95206409) table except for the fact that this table focuses on the errors and excludes the alerts triggered. <span style="color: #172b4d">You can see below the most relevant fields included in this table along with a brief explanation.</span>

| **Field** | **Data type** | **Description** |
| --- | --- | --- |
| *alertHost* | `str` | [Internal field:] this field indicates an internal Devo component related to alert dispatching. |
| *errorCode* | `str` | Explanation about the reason for the alert not being triggered. The most common are:<br>- Due to post-filter conditions
- Due to system anti-flooding |
| *domain* | `str` | Domain to which the alert belongs. |
| *priority* | `float` | Priority level assigned to the alert, represented as a numerical value:<br>- 0 → Very low
- 3 → Low
- 5 → Normal
- 7 → High
- 10 → Very high |
| *context* | `str` | Contextualization of the alert resulting from a combination of its category, domain and name.<br>> ℹ️ **Special characters in the alert name**
> ℹ️ 
> ℹ️ Alert names are normalized upon creation, replacing all special characters (not alphanumeric) by underscores (_). |
| *category* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *status* | `int` | Condition of the triggered alert regarding their life cycle, represented as a numerical value:<br>- Unread → 0
- Updated → 1
- Watched → 100
- False positive → 2
- Closed → 300
- Suppressed → 800 |
| *alertId* | `str` | Unique ID assigned to the alert when triggered. |
| *srcIp* | `ip4` | [Deprecated field:] information is not provided in this field anymore. |
| *srcPort* | `int` | [Deprecated field:] information is not provided in this field anymore. |
| *srcHost* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *dstIp* | `ip4` | [Deprecated field:] information is not provided in this field anymore. |
| *dstPort* | `int` | [Deprecated field:] information is not provided in this field anymore. |
| *dstHost* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *protocol* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *username* | `str` | User who created the alert definition. |
| *application* | `str` | [Deprecated field:] information is not provided in this field anymore. |
| *engine* | `str` | [Internal field:] this field indicates an internal Devo component related to alert dispatching. |
| *extraData* | `str` | Information extracted from different fields to indicate the conditions that triggered the alert (more info [here](https://devodocs.atlassian.net/wiki/spaces/latest/pages/576552961)). |
| *AlertContextSubscription* | `int` | [Deprecated field:] information is not provided in this field anymore. |
| *Alertcreationdate* | `timestamp` | Exact date on which the specified alert conditions were met but did not trigger an alert due to an error, which may indicate a slight delay with the event date (date on which the error event was registered in the Devo table). |

## `devo.audit.alert.definition`

In this table, you can find detailed information about all [alerts defined](https://devodocs.atlassian.net/wiki/spaces/latest/pages/529170511) in the current domain and the changes they undergo. You can see below the fields included in this table along with a brief explanation.

| **Field** | **Data type** | **Description** |
| --- | --- | --- |
| *actiondate* | `timestamp` | Date of the action performed. |
| *Id* | `str` | Unique ID automatically assigned to the alert when defined. |
| *name* | `str` | Name assigned to the alert when defined. |
| action | `str` | The action carried out, which can be one of the following:<br>- CREATE
- EDIT
- ENABLE
- DISABLE
- DELETE
- CREATE POST FILTER
- DELETE POST FILTER |
| *username* | `str` | User who performed the action.<br>> ℹ️ **admin.alerts@devo.com**
> ℹ️ 
> ℹ️ This user represents an internal entity responsible for enabling, disabling, or deleting alerts as an automatic or semi-automatic response to specific events. These events typically involve reattempts after failures, errors requiring immediate action to ensure proper functioning, or situations that activate [internal defense mechanisms](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95127672). |
| info | `json` | Detailed information about all settings of the alert definition being created or edited (name, description, subcategory, ID, triggering method, priority, etc.).<br>When the action involves enabling, disabling, or deleting the alert definition, this field will be empty.<br>When the action involves applying post-filters to an alert definition, the field contains the following info:<br>- Create: conditions set, id of the post-filter, name of the post-filter, action to be performed, and new value (when the action implies a change).  
Example → `{"conditions":["(eventdate) = (2024-11-12 14:29:06.072)"],"id":1236,"name":"My suppress filter","action":"change_status","value":"SUPPRESSED"}`
- Delete: id of the post-filter and name of the post-filter.  
Example → `{"id":1236,"name":"My suppress filter"}`<br>See [siem.logtrust.alert.info](https://docs.devo.com/space/latest/95206409/Alerts+monitoring#siem.logtrust.alert.info) for the meaning of numerical values in fields such as priority. |

## `devo.audit.alert.triggered`

In this table, you can find detailed information about all [alerts triggered](https://devodocs.atlassian.net/wiki/spaces/latest/pages/405700609) in the current domain and the changes they undergo. You can see below the fields included in this table along with a brief explanation.

Use an [alert definition](https://devodocs.atlassian.net/wiki/spaces/latest/pages/95126538) to create triggered alerts.  Sending data to this table will not add items to the [triggered alerts](https://devodocs.atlassian.net/wiki/spaces/latest/pages/405700609) interface.

| **Field** | **Data type** | **Description** |
| --- | --- | --- |
| hostname | `str` | Domain where the alert was triggered. |
| *actiondate* | `timestamp` | Date of the action performed. |
| *Id* | `str` | Unique ID automatically assigned to the alert when defined. |
| *name* | `str` | Name assigned to the alert when defined. |
| action | `str` | The action carried out, which can be one of the following:<br>- CREATE
- EDIT STATUS
- EDIT PRIORITY
- DELETE
- CREATE COMMENT
- REPLY COMMENT
- UPDATE COMMENT
- DELETE COMMENT |
| *username* | `str` | User who performed the action.<br>> ℹ️ **admin.alerts@devo.com**
> ℹ️ 
> ℹ️ This user represents an internal entity responsible for automatically registering alerts in the audit system when they are triggered. As a consequence, it only appears when the action is CREATE. |
| info | `json` | Whenever a modification is made to a triggered alert, the information related to the change is collected and displayed here to indicate the new values assigned.<br>Depending on the action (indicated in the action field), the displayed values vary:<br>- Create: the status and priority names, as well as the status and priority codes.  
E.g. → `{"statusName":"Unread","priorityName":"Low","statusCode":"0","priorityCode":"3.0"}`.  
  
The `appliedPostFilters` key includes an array of [post filters](https://devodocs.atlassian.net/wiki/spaces/latest/pages/405701006), if any were applied.
- Edit status: the new status code and the corresponding status name.  
E.g. → `{"statusCode":"100","statusName":"Watched"}`.
- Edit priority: the new priority and the corresponding priority name.  
E.g. → `{"priorityCode":"1.0","priorityName":"Very Low"}`.
- Deletion: empty.
- Comments: type of comment (ALERT-new comment vs REPLY), content of the message, ID assigned to the comment, and other IDs interrelating them with alerts and other comments. |