View Alert History

최신 업데이트:2026-08-20 16:13:38

Reading time: About 3 minutes

The Alert History page records all triggered alert events and data for their entire lifecycle. When a security incident occurs, you can use the alert level to prioritize your response, and check the alert details to understand the attack; after the incident ends, you can review the alert history to trace the root cause, evaluate response efficiency, and support the optimization of your monitoring strategy.

Path: Analysis & Logs > Alert Management > Alert History

Filter Alert Events

A single alert event records the entire process of an alert rule, from when it is first triggered to when it is finally resolved.

By default, the page displays the alert history generated today, sorted in descending order by First Triggered Time, with the most recent alert event pinned to the top. You can also perform a precise search for alert events:

Filter Condition Description
Time Range You can view up to the most recent six months of alert history.
Alert Status
Alerting: The period during which the alert condition continues to be met, starting from when the alert is first triggered. 
Cleared: The alert is cleared once the metric data that originally triggered it continuously meets the resolution condition.​​
Expired: If the associated alert rule is deleted, edited, or disabled while the alert is active, or if the monitored object is removed, the alert becomes invalidated. In this case, you cannot view the alert details for this alert event.
Alert Level Emergency, Critical, Warning

View Alert Details

After filtering, the system displays the alert events that match your criteria. Click the alert details icon in the list to view the details of an event:

Details Description
Alert Information Alert ID Each alert event has a unique alert ID
First Trigger Time
The time this alert event was first triggered
Note:
A single alert event can generate ​​multiple trigger records​​ — during each detection cycle, a new trigger record is generated whenever the metric reaches the threshold. For example, with a 1-minute statistical granularity:
09:00 threshold reached → ​​Trigger Record 1 
09:01 threshold not reached → ​​no trigger
​​ 09:02 threshold reached → ​​Trigger Record 2
Last Trigger Time The time of the most recent trigger within this alert event
Duration The amount of time this alert event has been ongoing
Alert Recovery Time The time this alert event was resolved
Time Zone The time zone configured for the system.
Note:​​The actual alert notification time is generated using a trigger timestamp based on the time zone configured in the alert rule; the time zone shown in the alert details always follows the system's global setting.
Trigger Alert Rule The name of the rule that triggered this alert event. Click it to go directly to that rule's details.
Alert Object Alert Object The monitoring object that triggered this alert event
Alert Details Trigger Content The specific content of each trigger record, including the filter fields and the triggering metric value
Trigger Time The time of each trigger record
이 문서의 내용이 도움이 되었습니까?
아니오
정상적으로 제출되었습니다.피드백을 주셔서 감사합니다.앞으로도 개선을 위해 노력하겠습니다.