About Alerts
The Skope IT Alerts page displays a log of alerts. You can click an alert to view additional details.
To view Skope IT Alerts monitored by the Netskope analytics engine, go to Skope IT > Events & Alerts > Alerts.
Default Alerts Page Table
The default Alerts page table includes:
- Time: The day and hour the alert occurred.
- Name: The policy that triggered the alert.
- Type: What triggered the alert, like policy, DLP, malware, anomaly, etc.
- Action: Type of remediation taken, like alert, block, and detection.
- Activity: What the user was doing when the violation occurred.
- Username: Email address of the user who caused the violation.
- Application: App used when the violation occurred.
- Site: Site where the violation occurred.
- Object: Actual file name, folder name, etc., that caused the alert. For example, a download activity shows an object value of CreditReportAAA111.pdf. Corresponds with the following column.
- Account Name: Name of the account.
Alerts Page Components
This Alerts page has these components:
- Alerts table: Displays specified alerts information. To change the information displayed, use the Customize Columns dialog box. Use the Sort By list in the table header row to arrange the listings in the table. Time is when the alert occurred in the cloud platform.
- Refresh Page button: To update the page with the most current information, click
next to the page title. - Customize Columns dialog box: To customize the columns shown for each alert, click the gear icon
located at the far right of the table column header row, and then select the columns you want to see. For more details, refer to Customize Columns below. - Date Range list: In the top right corner of the page is a date range filter. Click
and select a date range. The selection will be applied after clicking your selected date range.

- Application search filter: This search field helps you find applications and then filter results. Enter a name and then select from the list.
To Add a Filter

To add a filter do the following:
- Click the filter icon.
- To create a filter, click + Add Filter.
Select what to include what to find in the search, and then click Apply.
You can choose multiple items for some options. The options with the
icon allows you to search.
- Save Filter button: After adding a filter, you can save it for future searches by clicking Save Filter.

- Query Mode button: Optionally, switch to query mode
and enter a query in the search field. For example, to specify which app to search for, the domain, and the user’s email address, enter the following query. app eq 'Google Drive' and instance_id eq '<yourcompany.com>' and user eq '<user@yourcompany.com>'
- You can pin the query by clicking the pin icon
to remember the query across the Application Events, Page Events, and Alerts pages. - To change back to the filter view, click Filter Mode.

About Exporting
You can export data by clicking the EXPORT button.

How to Export
To export data complete the following steps:
- On the Alerts page, click the EXPORT button to open the export window.
- In the export window, make the following selections:
- Choose the columns to export:
- Displayed Columns: Choose to export the columns that are displayed on the Alerts page.
- Select Columns: Select the columns you want to export from the list by using the checkboxes.
- Select the number of rows:
- All Rows: Select all of the rows, up to 500,000 rows.
- Select Custom: Choose from 1,000, 10,000, or 100,000 rows.
- Export Name: Create a name for your export.
- Choose the columns to export:
- Click the EXPORT button within the export window to generate your customized export.
About Alert Details
Alert Details panel: Click the magnifying glass icon
besides any listing to view more details about the alert. The default view shows the alerts for the last 7 days unless you change the date range setting.
- Rows per page list: At the bottom right corner of the page, the Rows per page list allows you to display 10, 20, 30, 50, or 100 rows per page.
Customize Columns
Use the Customize Columns dialog box to specify the information you want to see.
To access the Customize Columns dialog box, click , and then select the information you want to see.
The Customize Columns window displays the following options:

- Alert: Includes categories like Time (GMT), Name, Alert Type, Action, Activity, and Incident ID.
If you have Endpoint Data Loss Protection, you can filter the Alert Type by Endpoint Content Control and Endpoint Device Control.
- General: Includes Transaction ID, Traffic Type, Access Method, Managed Application, Browser, Threat Type, DNS Query Type, and DNS Query Domain information.
- User: Includes Username, IP Address, Host Name, OS, OS Family, Device Type, Device Classification, Groups, and OU information.
- Application: Includes Application, Site, Category, CCL, Instance ID, and URL.
- Rule: Includes Policy Name, DLP Profile Name, DLP Rule Name, Remediated, Remediated On, Remediated By, and Remediated Action.
- General: Includes Traffic Type, Access Method, Managed Application, and Browser information.
- Object: Includes Object, Object Type, MD5, Resource Category, Object ID, and Resource Group.
- Source: Includes Source IP Address, Source Location, Source Region, Source ZIP Code, and Source Country.
- Destination: Includes Destination IP Address, Destination Host, Destination Port, Destination Location, and Destination Country.
Click Restore Defaults to restore column-related default settings.


