Real Time Alert Stabber
The real time alert stabber is designed to be the central place for viewing IDS alerts. The idea is to explore alert activity from various angles using animation and an interactive UI.
- Alerts activity over a period of time β say the past day
- Types & Priorities of alerts
- Individual alerts as they come in with details of endpoints
- Aggregated alert activity over the period of time
- Allow pivoting of view from alert signature, end points, priority, and classification
The bubbles are interactive β you can click on any of them to access various options. In keeping with overall Trisul philosophy you can pull up flows and packets for any alert.
Accessingβ
navigation
π To access select Dashboards β Real Time Alerts
Requirementsβ
The real time alert visualizer is a type of real time stabber. See the section of Real Time Stabbers for more. Since it requires browsers with support for WebSockets and LocalStorage, using the latest version of Google Chrome is a safe bet.
Using the Real Time Alert Stabberβ
Let us examine each section of the console.

Figure: Real Time Alerts Stabber Module