Skip to main content
Skip table of contents

Update the Alarm Status

LogRhythm SIEM, each alarm has a status:

  • New. When an alarm is first triggered, LogRhythm automatically assigns its status to New. An alarm can be changed back to a New state at any time. If you set an alarm back to a New state, the timestamps for when the alarm was set to Open and Closed are cleared. The date the alarm was generated is never cleared.
  • Open. A LogRhythm user opened the new alarm. In the Client Console, users can assign a sub-status of Working or Escalated.
  • Closed. The alarm is closed.
    In the Client Console, users can assign a sub-status of False Alarm, Monitor, Reported, Resolved, and Unresolved.

You can use the Web Console to set the Alarm Status to Open, Closed, or New.

Alarms that have a status of New or Open are considered Unclosed when using the Alarm Status filter in the alarm filter bar.


You can change in...
Alarm StatusClient Console:
Alarm History Window
Web Console:
Alarms Page
OpenXX
WorkingX
EscalatedX
ClosedXX
Closed sub-status: False Alarm, Monitor, Reported, Resolved, and UnresolvedX
NewXX

To update the status of individual alarms, do one of the following:

  1. On the top navigation bar, click Alarms.
    • In the Alarm card view:
      1. Next to the Alarm status, click the arrow.
      2. Select OpenClosed, or New.
    • In the Alarm grid view, do one of the following:
      • Change the status from the selection bar.
        1. Select the check box of the alarm you want to change.
        2. In the Status list in the selection bar, select OpenClosed, or New.
      • Change the status from the Inspector panel.
        1. Click anywhere in the row of the alarm you want to change.
        2. Click the Inspector tab to expand the Inspector panel, if necessary. 
        3. In the Alarm Actions section, click the arrow to expand the Status list.
        4. Select OpenClosed, or New.
    • At the top of the Analyze page, select the status from the list.

To update the status of multiple alarms at the same time, do one of the following:

  1. On the top navigation bar, click Alarms.
    • In the Alarm card view:
      1. Select multiple alarms by doing one of the following:
        • Select the check boxes on the alarms that you want to update.
        • On the alarm toolbar, select the Check Visible check box to select all visible alarms on the page.
      2. From the Status list on the alarm toolbar, select OpenClosed, or New to update all of the selected alarms.
    • In the Alarm grid view:
      1. Select multiple alarms by doing one of the following:
        • Select the check boxes on the alarms that you want to update.
        • At the upper-left of the Alarm grid, select Check All to select the first 100 alarms in the grid.
      2. In the Status list in the selection bar, select OpenClosed, or New to update all of the selected alarms.

To update all alarms associated with a case, do one of the following:

  1. On the top navigation bar, click Alarms.
  2. On the left side of the dashboard, click the Cases tab to open the Current Case panel. You can also open the Current Case panel by pressing C on your keyboard.
  3. In the evidence section, click the Change “X” alarms to list and select OpenClosed, or New to update all alarms that are associated with the case.

Alarms that are associated with a case can also be closed at the same time the case is closed. For more information, see Close Cases.

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.