Showing results for 
Show  only  | Search instead for 
Did you mean: 
Level 9
Report Inappropriate Content
Message 1 of 3

How to use 'Alarms' Dashboard

We're trying to figure out the best way to use the Alarms dashboard. We're unable to figure out how to use the 'Alarms' in a way that allows us apply basic SOC workflow functions. 

  1.  Alarm triggers
  2. Analysts acknowledges alarm
  3. Analyst begins triage
  4. Analyst decides to dismiss alarm (FP, etc) or decides to escalate (create case)

We know we can create a case easily from here, but what we cannot figure out is how/where the analyst is supposed to manage and disposition the alarm. I don't see any place to disposition or dismiss the alarm. Or to add any type of notes to the alarm. I also dont see a way to associate or collapse multiple alarms into one. 

I don't think it's realistic to move all alarms into a case management system. Is there something that I'm missing here?


Labels (3)
2 Replies
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 2 of 3

Re: How to use 'Alarms' Dashboard

no, your not missing nothing.

theirs' no option of leaving notes etc. on the Alarms...

i posted a idea for that in the McAfee Ideas Site, but they just closed it...

sadly, no option.


Best Regards👍👍👍


Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 3 of 3

Re: How to use 'Alarms' Dashboard

The case management inside the SIEM is pretty terrible, it was clearly added as an after though. 

Most alarms that I make are basically just "auto-acknowledged" and tied to some event, such as emailing, adding things to watchlists, etc...

You might want to try to do an integration to a ticketing system to really track things a little better.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community