---
title: "Alerting Page"
slug: "alerting-page"
description: "Explore the Kentik Alerting page, featuring real-time alerts, severity levels, and detailed metrics for effective network monitoring and management."
updated: 2026-07-16T20:24:34Z
published: 2026-07-17T00:44:38Z
canonical: "kb.kentik.com/alerting-page"
stale: true
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.kentik.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Alerting Page

This article covers the **Alerting** page in the Kentik portal.

> [!NOTE]
> **Note:** For an introduction to Kentik's alerting systems, see [**Alerting**](/v1/docs/alerting-4).

![Kentik's Alerting page displaying active alerts with severity levels and detailed metrics for monitoring.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-alerting-page-main.png)

*The Alerting page lists recent alerts generated by alert policies*

The **Alerting** page lists current and historical alerts from Kentik's alerting system, including alert time, severity, and state, and the dimensions/metric values defined in the alert conditions.

The page includes the following UI elements:

- **Favorite**: A star to the left of the page title, allowing you to add it to the **Favorites** tab (see [**Portal Search Tabs**](/v1/docs/portal-overview#portal-search-tabs)).
- **Alerting Trends** (button): Opens the [**Alerting Trends**](/v1/docs/alerting-trends) page.
- **Manage Alert Policies** (button): Opens the [**Alert Policies**](/v1/docs/alert-policies-2#alert-policies-page-ui) page.
- **Actions** (button): Opens the [**Page-Wide Actions Menu**](/v1/docs/alerting-page#pagewide-actions-menu).
- **Alerting Breakdowns**: Cards with bar charts showing alert breakdowns by category (state, severity, type, policy, see [**Alerting Breakdowns**](/v1/docs/alerting-page#alerting-breakdowns)).
  - Breakdowns cover the time range selected in the Filters tab (see [**Alerts Filters**](/v1/docs/alerting-page#alerts-list-filters)).
  - Hover over a bar to open a popup with additional information.
- **Show/Hide Filters** (filter icon): Toggles the expanded/collapsed **Filters** pane.
- **Group By**: A selector to organize the Alerts list by properties like alert state, ack state, severity, type, or policy. Default: None.
- **Search** (field): Shows lozenges for any filters applied via the Filter pane, and allows text input for further filtering. Click the **X** next to the field to clear entered text. Click **X** in a lozenge to clear the corresponding filter.
- **Filters** (pane): Controls for filtering the Alerts list (see [**Alerts Filters**](/v1/docs/alerting-page#alerts-list-filters)).
- **Alert Controls**: Apply actions to all selected alerts (controls activate when at least one alert is selected):
  - **Action buttons**: Click to apply actions such as **Acknowledge Alert** (see [**Alert Controls**](/v1/docs/alerting-page#alert-controls)).
  - **Selection count**: Shows the number of selected alerts.
- **Alerts List**: A table listing your organization’s alerts (see [**Alerts List**](/v1/docs/alerting-page#alerts-list)).

> [!TIP]
> **Tip**: This page also provides access to the [**Alert Policies**](/v1/docs/alert-policies-2#alert-policies-page-ui) page, where you can manage and configure alert policies and system responses to alerts (e.g., notifications and mitigations).

### Page-Wide Actions Menu

This menu opens with the **Actions** button at the top right of the Alerting page. It includes:

- **Export**: Prepares a report (notification appears when ready to download).
  - **Visual report (PDF)**: See [**Portal Export Options**](/v1/docs/portal-sharing-and-export#portal-export-options).
  - **Data table (CSV)**: Opens a dialog with the following:
    - ![Options for exporting alerting data, including columns and data selection.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/Alrt-Export_data_dialog.png)**Columns to Export**: Choose the columns to export to the CSV file (currently visible columns or all columns).
    - **Data To Export**: Select the rows to export to the CSV file (currently loaded rows or the first 200, 500, 1000, or 2000 rows).
    - **Export** (button): Click to close the dialog and start the alerting data export.

> **Note**: A notification appears at the top of your screen when the report is ready to download.
- **Subscribe**: Opens the Subscribe dialog to create an alert subscription. See [**Subscription Tab UI**](/v1/docs/portal-sharing-and-export#subscription-tab-ui) for details, noting that this dialog also includes the Share, Selected View, and Lookback fields.
- **Unsubscribe**: Opens the Unsubscribe dialog to remove an alert subscription. Select the subscription to unsubscribe from the dropdown and click **Unsubscribe.**

> [!NOTE]
> **Note**: The Unsubscribe option appears only if you’re subscribed to one or more alert subscriptions.

## Alerting Breakdowns

Cards across the page display bar charts representing a different breakdown of alerts over the selected **Time Range** (see [**Filter Categories**](/v1/docs/alerting-page#filter-categories)). Hovering on any bar opens a popup showing the kind and count of alerts. Clicking any bar adds a corresponding filter lozenge to the **Search** field, showing only alerts matching the clicked state, severity, type, or policy.

> [!NOTE]
> **Note:** Adding a breakdown filter:
> 
> - Replaces any existing breakdown filter.
> - Can change the **Filters** pane settings, which won’t revert when the breakdown filter is removed.

![](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/image(137).png)

*Bar charts show the breakdown of different kinds of alerts in various categories.*

Each category has a breakdown chart with bars representing various alert properties:

- **State**: Red bars represent active alerts, green bars represent cleared alerts.
- **Severity**: Bars represent alerts by their severity level (see [**General Settings**](/v1/docs/flow-policy-settings#general-policy-settings)):
  - Critical (dark purple)
  - Severe (plum)
  - Major (red)
  - Warning (orange)
  - Minor (yellow)
- **Type**: Bars represent alerts by type: NMS, Traffic, or Protect.
- **Policies**: Bars represent individual policies that triggered during the selected time range, arranged in descending order based on alert count. Hover on a bar to view the name, type, ID, and alert count for the policy.

## Alerts Filters

The **Filters** pane includes filters to narrow the Alerts list based on the [**Filter Application Rules**](/v1/docs/alerting-page#filter-application-rules1) and [**Filter Categories**](/v1/docs/alerting-page#filter-categories), and has these main controls:

- **Reset to default** (button): Resets the **Filters** pane to its default settings (only available when filters are specified).
- **Collapse** (button): Collapses the **Filters** pane. Expand it by clicking the funnel icon.

> [!NOTE]
> **Notes:**
> 
> - All filters from a category are combined into a single lozenge in the **Search** field. Click the **X** in the lozenge to remove all filters from that category.
> - You can change the start and end time values before applying the filter.

### Filter Application Rules

Kentik applies the following rules to filter categories and criteria:

- Alerts are displayed only if they match at least one selected criterion in all selected categories.
- Alerts are not evaluated for matches in categories with no selected criteria.

### Filter Categories

Filter criteria for the Alerts list fall into the following categories:![The Filters pane with selections available for Time Range, Type, Alert State, Ack State, and Severity.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-alerting-page-filters.png)

- **Time Range (UTC)**: Specify a time range for the listed alerts.
  - This control filters alerts in the Alerts list to those active within a specified time range (UTC), e.g., last hour, last 24 hours (default), last 7 days, etc. or a custom time range (see [**Custom Time Range Settings**](/v1/docs/query-settings-overview#custom-time-range-settings)).
  - Select a time range and click **Apply** to apply the time range or **Cancel** to exit without saving.
- **Type** (checkboxes): Filter alerts by type: NMS, Traffic, or Protect (see [**Policy Types**](/v1/docs/alerting-4#policy-types)).
- **Alert State** (checkboxes): Filter alerts by [**Alert State**](/v1/docs/alerting-page#alert-state) (Active or Cleared).
- **Ack State** (checkboxes): Filter alerts by [**Ack State**](/v1/docs/alerting-page#ack-state) (Ack Required, Acked, Not Acked, or Acked by Me).
- **Severity** (checkboxes): Filter alerts by severity (Critical, Severe, Major, Warning, or Minor), as determined by the alert policy threshold that triggered the alert.
- **Alert ID** (text field): Filter alerts by Kentik-assigned ID number (no partial matches).
- **Sites** (selection field): Include only alerts for the selected sites.
- **Policies** (selection field): Include only alerts for the selected policies.
- **Show Tenant Alerts**: When enabled:
  - Allows [**My Kentik Portal**](/v1/docs/my-kentik-portal) tenant alerts to be displayed in the Alerts list.
  - Displays the **Tenants** selection field.

> [!NOTE]
> **Note**: To show tenant alerts, click **Customize** at the top right of the Alerts list to display the [**Customize Columns Popup**](/v1/docs/alerting-page#customize-columns-popup) and select **Tenant**.
- **Tenants** (selection field): Include only alerts for the selected tenants (active only when **Show Tenant Alerts** is enabled).
- **Dimension Value** (text field): Include alerts where the dimension in the alert policy matches the entered text.
- **Has AI Investigation** (checkbox): A standalone toggle to filter the list to only display alerts that have an associated AI investigation.
- **External Context** (checkboxes): Filter alerts that are linked to configured third-party ITSM or ticketing integrations (e.g., ServiceNow, Jira).

## Alerts List

The Alerts list is a filterable table (see [**Alerts Filters**](/v1/docs/alerting-page#alerts-list-filters)) that shows information about alerts triggered by your organization's alert policies. Each row represents an alert. Click a row to open the [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1) for more details.

![The Alerts list with active alerts showing severity levels and details for network incidents and metrics.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-alerts-list-selected-rows.png)

*Individual alerts are selected with the checkbox at the left of their row.*

### Alerts List Columns

The columns shown in the Alerts list are customizable via the [**Customize Columns Popup**](/v1/docs/alerting-page#customize-columns-popup). The available columns are:

- **Select All** (in header row): Click the checkbox to select all alerts. Click it again to deselect all alerts.
- **Select** (in alert rows): Click a checkbox to select individual alerts. Once alerts are selected, the [**Alert Controls**](/v1/docs/alerting-page#alert-controls) appear at the top left of the list.
- **Alert State**: The alert’s current state (see [**Alert State**](/v1/docs/alerting-page#alert-state)).
- **Severity**: The severity level (Critical, Severe, Major, Warning, or Minor) as determined by the alert policy threshold.
- **Type**: The alert policy type: NMS, Traffic, or Protect (see [**Policy Types**](/v1/docs/alerting-4#policy-types)).
- **Policy**: The alert policy name.
- **Policy ID**: The unique policy ID.
- **Tenant**: If enabled, includes alerts from the tenant (see [**Tenants and Packages**](/v1/docs/my-kentik-portal#tenants-and-packages)). Active only when you enable **Show Tenant Alerts** in the [**Alerts Filters**](/v1/docs/alerting-page#alerts-list-filters).
- **Dimensions**: The key definition’s dimensions and their values for the keys that triggered the alert (see [**Dimensions Reference**](/v1/docs/non-flow-metrics)). For example, if the key definition is `Dest IP, Device` the dimensions column might show `Dest IP:1.10.1.174` and `Device:s414_ida9_nektie_com`.

> [!NOTE]
> **Note:** If a dimension value is blue, you can click it to go to its Details page (see [**Core Details Pages**](/v1/docs/core-details-pages)).
- **Metric**: The volume of traffic matching the key. The top-X ranking is based on the volume of matching traffic measured in the primary metric (see [**Dataset Settings**](/v1/docs/flow-policy-settings#policy-dataset-settings)).
- **Mitigation ID**: The unique mitigation ID. Click to open the [**Mitigations**](/v1/docs/mitigations-page) page in a new tab, filtered for that ID.
- **Alert ID**: The unique alert ID. Click to open the alert’s [**Alert Details**](/v1/docs/alert-details#alert-details-page1) page in a new tab.
- **Time (UTC)**: Displays the precise timestamp when the alert event started, along with its current total duration, e.g., Start: 2026-09-02, Duration: 5 minutes.
- **Silence State**: Indicates whether the alert’s notifications are paused ("Silenced" plus the expiration date of the pause) or not ("Not Silenced").
- **Ack State**: The alert’s acknowledgement state (e.g., “Ack Required”; see [**Ack State**](/v1/docs/alerting-page#ack-state)).

> [!NOTE]
> **Note**: If the state is "Acked," the column also displays the alert’s acknowledgement time and user.
- **Action menu**: A vertical dots icon at the right of each alert row, which opens a menu for actions to take on that alert (see [**Alert-Specific Actions**](/v1/docs/alerting-page#alertspecific-actions)).

> [!NOTE]
> **Note:** Alert policies don't generate alerts when in error states. If you don’t see alerts when expected, check the **Policy Status** on the [**Alert Policies**](/v1/docs/alert-policies-2#alert-policies-page-ui) page (see [**General Settings**](/v1/docs/flow-policy-settings#general-policy-settings)).

#### Alert Controls

When one or more alerts are selected, the following controls appear above the Alerts list:

- **Acknowledge Alert** (button): Click to acknowledge that you’ve seen the alert (see [**Acknowledging Alerts**](/v1/docs/alerting-page#acknowledging-alerts)).
- **Clear Alert** (button): Click to change the [**Alert State**](/v1/docs/alerting-page#alert-state) from Active to Cleared. You can do this regardless of the alert’s [**Ack State**](/v1/docs/alerting-page#ack-state) or if the conditions that triggered the alarm are still present.

> [!NOTE]
> **Note**: Either button may be greyed out if the selected alerts have already been acknowledged and/or cleared.

#### Customize Columns Popup![Options to customize visible columns including Severity, Alert State, and Time (UTC).](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-alerts-page-customize-columns.png)

Choose up to 11 columns to include in the Alerts list using the Customize Columns popup. To access, click the **Customize** button at the top right of the list. The popup includes the following UI elements:

- **Choose columns**: Check the boxes next to the columns to include them in the table.
- **Order columns**: Drag the handles next to the checkboxes to reorder the columns.

When finished, click outside to close the popup and return to the Alerts list.

## Alert Summary Drawer

The Alert Summary drawer slides out from the right of the Alerting page when you click anywhere in the [**Alerts List**](/v1/docs/alerting-page#alerts-list) row for an alert. The information in the drawer varies depending on the alert type and available information:

- ![Alert Details drawer showing critical ICMP attack details for tenant pear inc.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-alert-details-drawer(1).png)**Alert Metadata Header**: Appears directly above the title, displaying the policy type, severity level, and current duration of the alert (e.g., Traffic • Severe • Active for 4m)
- **Policy/Title**: The name of the alert policy that triggered the alert (see [**Alert Policies**](/v1/docs/alert-policies-2)).
- **View Alert Details** (button): Opens the [**Alert Details**](/v1/docs/alert-details#alert-details-page1) page for the selected alert.
- **+ Investigate with AI Advisor** (button): Opens AI Advisor in overlay mode and starts a troubleshooting session for the selected alert.
- **View in Metrics Explorer** (NMS only): Opens [**Metrics Explorer**](/v1/docs/metrics-explorer) with the alert policy’s settings pre-populated in the Query sidebar.
- **Lookback** (NMS only): A dropdown to set the visualization time range.
  - **Options**: Alert +/- 1 hour (default), Alert +/- 24 hours, Last hour, Last day, Last 7 days, Last 14 days, and Last 30 days.
  - The graph shows between 1 and 24 hours before the alert was triggered until the current time.
- **Visualization**: A visualization is available for most alerts, appropriate to the alert type:
  - **Threshold alerts**: A traffic representation with context (baseline and thresholds) for why the alert triggered.
  - **NMS alerts**: Displays standard line charts for metrics or an [**Up/Down Visualization**](/v1/docs/alert-details#updown-visualization).
- **Ack statement**: Displays who acked the alert and at what time. If a comment was added, it will display here in addition to in the [**Comments Pane**](/v1/docs/alerting-page#comments-pane).
- **Alert Overview**: Displays key alert information (see [**Alert Overview**](/v1/docs/alerting-3#alert-overview)).
- **Target** (not present for NMS alerts): Shows the key dimension (target) that matched the threshold conditions, along with the values, from the Dimensions and Metric columns of the Alerts list (plus any secondary metrics).
- **Triggering Event**: The alert policy conditions that triggered the alert (see [**Triggering Event**](/v1/docs/alerting-3#triggering-event)).
- **Triggered Threshold**: A summary of the policy’s [**Triggered Threshold**](/v1/docs/alerting-3#triggered-threshold), including dimensions, primary and secondary metrics, conditions, and activation/clearance times.
- **Mitigation Details**: Information about automatically triggered the mitigations (if defined by the alert policy) including ID, start date/time, platform, and method.
- **Comments**: A field to add comments and view [**Alert Comments**](/v1/docs/alerting-3#alert-comments) already added (see [**Comments Pane**](/v1/docs/alerting-3#comments-pane)).
- **Take Action**: Buttons for additional alert-related actions (see [**Alert-Specific Actions**](/v1/docs/alerting-page#alertspecific-actions)).
- **Warning**: If the policy has changed since alert activation, a sidebar warning might appear in the affected sections.

### Alert Overview

The **Alert Overview** section in the Alert Summary drawer offers the following information:

- **ID**: The system-generated unique ID for the alert. Click it to open the [**Alert Details**](/v1/docs/alert-details#alert-details-page1) page in a new tab.
- **Severity**: The alert’s severity level (Critical, Severe, Major, Warning, or Minor). Severity is determined by the alert policy threshold that triggered the alert.
- **Alert State**: The state of the alert (Active or Cleared). See [**Alert State**](/v1/docs/alerting-page#alert-state).
- **Ack State**: The acknowledgement state of the alert (Ack Required, Acked, or Not Acked). See [**Ack State**](/v1/docs/alerting-page#ack-state).
- **Start Time**: The start of the period evaluated for the alert.
- **Event End Time**: The end of the period evaluated for the alert, calculated based on the counter reset time on the policy for threshold alerts.
- **Clear Time**: The end of the period evaluated for the alert or "Currently Active" if the alert is ongoing.

### Triggering Event

The **Triggering Event** section of the Alert Summary drawer depends on the alert type:

- **Traffic/Protect**: A Traffic/Protect alert’s Triggering Event section provides:
  - **Type**: Indicates the evaluation method used by the threshold that triggered the alert, typically "Static" (a fixed limit) or "Baseline" (compared against historical data).
  - **Policy Conditions**: The specific rule or threshold limit defined in the alert policy that the traffic had to meet or exceed to trigger the alert (e.g., `≥ 50.00 Kpackets/s` or `≥ 75% below baseline`).
  - **Triggering Value**: The actual measured metric value of the traffic at the moment it breached the policy condition (e.g., `79.33 Kpackets/s`).
  - **Triggering Context:** Text beneath the Triggering Event table that quantifies how far the metric exceeded the condition (e.g., "63.96 packets/s above policy condition") and indicates if a baseline was used.
- **NMS**: An NMS alert’s **Triggering Event** section provides:
  - **Metrics**: The metrics that triggered the alert as displayed in the Metric column (see [**Alerts List Columns**](/v1/docs/alerting-page#alerts-list-columns)).
  - **Dimensions**: The dimensions that triggered the alert as displayed in the Dimensions column (see [**Alerts List Columns**](/v1/docs/alerting-page#alerts-list-columns)).
  - **Context**: The policy’s selected measurement (see [**Measurement Pane Parameters**](/v1/docs/metrics-explorer#measurement-pane-parameters)) and the affected device name (see [**NMS Device Details Page**](/v1/docs/nms-devices)).
- **NMS (Syslog only)**: An NMS alert’s **Triggering Syslog Event** section provides:
  - **Severity:** The severity level extracted from the raw syslog message itself (e.g., `Critical`, `Error`, `Warning`).
  - **Timestamp:** The exact time the syslog message was generated, displayed in the UI as an epoch timestamp (e.g., `1784048690000`).
  - **Message:** The full, raw text string of the syslog message containing the specific event details, status codes, and contextual data sent by the device.
  - **Device:** The hostname or specific identifier of the network element that generated the syslog message (e.g., `pan-fw-s2s-2026`).

### Triggered Threshold

The **Triggered Threshold** section of the Alert Summary drawer provides the following about the policy threshold that triggered the alert (when applicable):

- **Dimensions**: The dimensions used to evaluate traffic for the threshold (see [**Dataset Settings**](/v1/docs/flow-policy-settings#policy-dataset-settings)).
- **Primary and Secondary Metrics**: The metrics used to evaluate traffic for the threshold [**Dataset Settings**](/v1/docs/flow-policy-settings#policy-dataset-settings)).
- **Conditions**: Match criteria (see [**Threshold Conditions**](/v1/docs/flow-policy-settings#conditions2)).
- **Activates**: The required number of matching conditions within the specified time period (see [**Threshold Frequency**](/v1/docs/flow-policy-settings#frequency)).
- **Clears**: Time after which the counter resets if conditions aren’t met (see [**Threshold Frequency**](/v1/docs/flow-policy-settings#frequency)).

### Mitigation Details

The **Mitigation Details** section of the Alert Summary drawer provides the following about any mitigations triggered by the policy’s threshold (see [**Mitigation Overview**](/v1/docs/mitigation-overview)):

- **ID**: The system-generated unique ID for the mitigation. Click it to open the [**Mitigations List**](/v1/docs/mitigations-page#mitigations-list) filtered for this ID.
- **Started**: The date and time the mitigation was initiated.
- **Platform**: The platform on which the mitigation was exec (see [**Platforms and Methods**](/v1/docs/manage-mitigations#getting-started)).
- **Method**: The individual configuration that ran on the mitigation platform (see [**Platforms and Methods**](/v1/docs/manage-mitigations)).

### Comments Pane

The **Comments** pane of the Alert Summary drawer allows you to add and manage comments for a single alert. It’s also found in the [**Alert Details Page Sidebar**](/v1/docs/alert-details#alert-details-page-sidebar), and includes the following UI elements:

- ![](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/image(232).png)**Comment count**: The number of comments, in parentheses next to the heading.
- **Comment card**: Each alert comment added shows as a separate card with the following elements:
  - **Ack statement**: Displays the user who acked the alert and when.
  - **Edit** (only for the original commenter): Allows modifying the comment. Click **Save** to update the comment or **Cancel** to exit without saving changes.
  - **Remove** (only for the original commenter): Opens a confirmation dialog to remove the selected comment.
  - **Comment**: The original comment.
- **Add Comment**: A field to add a comment to the alert (see [**Add an Alert Comment**](/v1/docs/manage-alerts#add-an-alert-comment)).

### Take Action Pane

The **Take Action** pane of the Alert Summary drawer is described in [**Alert-Specific Actions**](/v1/docs/alerting-page#alertspecific-actions).

## Alert-Specific Actions

Actions can be applied to an individual alert from the following locations:

- ![Menu options for managing alerts including actions like silence and debug alerts.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-alert-specific-actions.png)

**Action menu**: In the [**Alerts List**](/v1/docs/alerting-page#alerts-list)**,** click the vertical dots icon for an alert to open a list of actions.
- **Take Action**: A list of buttons (varying by alert type) that appear in the following areas of the portal:
  - [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1)
  - [**Alert Details Page Sidebar**](/v1/docs/alert-details#alert-details-page-sidebar)
  - [**NMS Alert Details Sidebar**](/v1/docs/alert-details#nms-alert-details-sidebar)
  - [**Attack Details Drawer**](/v1/docs/ddos-defense#attack-details-drawer)

### Available Actions

Available actions vary depending on the alert’s state or your location in the portal, and may include:

- ![Menu options for managing alerts including viewing, investigating, and editing policies.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/AL-take-action.png)**View Alert Details**: Opens the alert’s [**Alert Details**](/v1/docs/alert-details#alert-details-page1) page in a new tab.
- **Investigate with AI Advisor**: Open a new conversation with Kentik’s AI agent about this alert (see [**AI Advisor**](/v1/docs/ai-advisor)).
- **Ack Alert**: Opens the [**Acknowledge Alert Dialog**](/v1/docs/alerting-page#acknowledge-alert-dialog) to confirm you’ve seen the alert.
- **Remove Ack**: Change the ack state back to “Not Acked” or “Ack Required” (as per alert policy).
- **Clear Alert** (Take Action section only): Manually change [**Alert State**](/v1/docs/alerting-page#alert-state) from “Active” to “Cleared”, regardless of [**Ack State**](/v1/docs/alerting-page#ack-state) or trigger conditions being met.
- **Silence Notifications**: Pause alert notifications for seven days.
- **Unsilence Notifications**: Lift the pause on alert notifications.
- **Suppress Alert**: Clear the alert and prevent policy from alerting on same key for seven days (see [**About Alert Suppressions & Silences**](/v1/docs/alert-suppressions#about-alert-suppressions-silences)).
- **Add Comment** (Action menu only): Add alert comment (see [**Alert Comments**](/v1/docs/alerting-page#alert-comments)).

> [!NOTE]
> **Note**: A **Comments** field appears above the **Take Action** section in all other areas.
- **Start Manual Mitigation…**: Opens the [**Start Manual Mitigation**](/v1/docs/manual-mitigation#start-manual-mitigation-dialog) dialog to start a manual mitigation for this alert.
- **View Dashboard**: Opens the dashboard specified the in Policy Dashboard setting (see [**General Settings**](/v1/docs/flow-policy-settings#general-policy-settings)).
- **Edit Policy**: (Take Action section only): Go to the Edit Policy page for the alert policy (see [**Policy Settings Pages**](/v1/docs/alert-policies-2#policy-settings-pages)).
- **Debug Alert**: Open the [**Alert Debug Dialog**](/v1/docs/alerting-page#alert-debug-dialog) for this alert.

### Alert State

There are two possible states for alerts in Kentik:

- **Active**: The alert conditions are still present; displayed as a red lozenge.
- **Cleared**: The alert has been manually cleared or the conditions are no longer present; displayed as a green lozenge.

> [!NOTE]
> **Note:** You can narrow the Alerts list based on state using the **Alert State** filters (see [**Alerts Filters**](/v1/docs/alerting-page#alerts-list-filters)).

### Ack State

Any alert can be acknowledged ("acked") by users with access to Kentik’s Alerting or DDoS Defense pages. The following alert ack states are available:

- **Ack Required**: The alert requires acknowledgement and hasn’t been acknowledged.
- **Acked**: The alert has been acknowledged.
- **Not Acked**: The alert hasn’t been acknowledged.
- **Acked by Me** (**Filters** pane only): Filters the Alerts list for alerts you’ve acknowledged.

Alert ack state is available in the following places in the Kentik portal:

- **Alerting Page**:
  - [**Alerts List**](/v1/docs/alerting-page#alerts-list): Ack State column
  - [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1)**:** Alert Overview section
  - [**Alert Details Page Sidebar**](/v1/docs/alert-details#alert-details-page-sidebar): Alert Overview section
- [**DDoS Defense Page**](/v1/docs/ddos-defense#ddos-defense-page):
  - “Attacks Active Within the Last 24 Hours” table

### Alert Comments

When acknowledging an alert in the [**Acknowledge Alert Dialog**](/v1/docs/alerting-page#acknowledge-alert-dialog), you can add a comment visible by other users.

- **All Alerts**: Alert comments appear in the [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1) and [**Alert Details Page Sidebar**](/v1/docs/alert-details#alert-details-page-sidebar):
  - **Ack statement**: The comment appears under the traffic chart, along with the user name who acked the alert.
  - **Comments pane**: Comments are displayed as cards in chronological order. You can add another comment in the **Comment** field below any existing comments (see [**Comments Pane**](/v1/docs/alerting-page#comments-pane)).
- **Auto-acknowledged Alerts Only**: Alert comments also appear in the [**Auto-acknowledgements Page**](/v1/docs/auto-acknowledgements#autoacknowledgements-page).

> [!NOTE]
> **Note:** For step-by-step procedures, see [**Add an Alert Comment**](/v1/docs/manage-alerts#add-an-alert-comment), [**Edit an Alert Comment**](/v1/docs/manage-alerts#edit-an-alert-comment), and [**Remove an Alert Comment**](/v1/docs/manage-alerts#remove-an-alert-comment).

### Acknowledge Alert Dialog

Access the Acknowledge Alert dialog from these portal locations:

- Click **Acknowledge Alert** above the Alerts list (see [**Alert Controls**](/v1/docs/alerting-page#alert-controls)).
- Choose **Ack Alert** from the Action menu at the right of each Alerts list row (see [**Alert-Specific Actions**](/v1/docs/alerting-page#alertspecific-actions)).
- Click **Ack Alert** in the **Take Action** pane of the [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1).
- Click **Ack Alert** in the [**Alert Details Page Sidebar**](/v1/docs/alert-details#alert-details-page-sidebar).

#### Ack Alert Dialog UI

The Acknowledge Alert dialog has the following UI elements:

- ![Alert acknowledgment options including duration and notification settings for River Song.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/Alrt-Ack_Alert_dialog.png)**Cancel** (buttons): Click the **X** at top right or **Cancel** at bottom to close the dialog without acknowledging the alert.
- **Acknowledgement info**: A statement identifying you as the person that acknowledged the alert (see [**Acknowledging Alerts**](/v1/docs/alerting-page#acknowledging-alerts)).
- **Comment**: A field to input a comment for the alert (see [**Alert Comments**](/v1/docs/alerting-page#alert-comments)).
- **Acknowledge additional occurrences (auto-ack)**: A checkbox to enable auto-acknowledgement for this alert. When checked, the **Duration** controls are shown.
- **Silence notifications for this alert**: A checkbox to silence notifications for this alert for the specified duration (see [**Silence Alert Notifications**](/v1/docs/manage-alerts#silence-alert-notifications)). When checked, the **Duration** controls are shown.

> [!NOTE]
> **Note**: This option is not active when the alert has already been silenced.
- **Duration**: Specify a duration for auto-acknowledgement and/or silencing notifications. The method is chosen by radio button:
  - **For**: Specify a duration forward from the present in either hours or days (whole numbers only).
    - **Hours**: The duration must be between 1 and 24 hours.
    - **Days**: The duration must be between 0 and 7 days for Member-level users, or up to 365 days for Admin-level users.
  - **Until**: Specify a future date-time at which the duration will expire.
    - Click the field to open the calendar.
    - Enter a date-time at least 1 hour and up to 7 days from the present for Member-level users, or up to 365 days for admin-level users.
- **Confirm**: Click to acknowledge the alert, save changes, and exit the dialog.

> [!NOTE]
> **Note**: You cannot set separate time durations for the “auto-ack” and “silence” features. The selected duration applies to both.

## Acknowledging Alerts

Acknowledging alerts informs other users that you are aware of them. When you acknowledge (ack) an alert, your **Full Name** from your user profile (see [**General Settings**](/v1/docs/user-profile#general-settings)) appears with ack state “Acked” in these locations of the portal:

- **Alerting Page**: **Ack State** column of Alerts list. In **Details** drawer.
- [**DDoS Defense Page**](/v1/docs/ddos-defense#attack-table): **Ack State** column of Attack table. In **Details** drawer.
- [**Alert Details Page**](/v1/docs/alert-details#alert-details-page1): **Ack State** column of **Alert Overview** sidebar.

You can acknowledge an alert type (Protect, Cloud, Traffic, NMS) regardless of **Acknowledgement Required** being enabled in the policy threshold. Each alert can be acknowledged by one user at a time, but if removed (see [**Remove an Alert Ack**](/v1/docs/manage-alerts#remove-an-alert-ack)) another user can acknowledge the same alert (see [**Acknowledge an Alert**](/v1/docs/manage-alerts#acknowledge-an-alert)).

### Auto-Acknowledgement

Auto-acknowledgement allows you to set a duration for automatic acknowledgement of all instances of a given alert (triggered by a policy threshold and based on the same key). The minimum duration is one hour, and the maximum is seven days for member-level users or one year for admin-level users. The duration is set when you [**Auto-acknowledge an Alert**](/v1/docs/manage-alerts#autoacknowledge-an-alert) and can be managed on the [**Auto-acknowledgements**](/v1/docs/auto-acknowledgements) page.

### Silence Notifications

To silence notifications for a given alert for seven days, click **Silence Notifications** in one of the following locations:

- **Alerting Page**:
  - In the [**Alert-Specific Actions**](/v1/docs/alerting-page#alertspecific-actions) menu for the alert.
  - In the [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1), under Take Action.
- [**Alert Details Page**](/v1/docs/alert-details#alert-details-page1):
  - Under Take Action.

You can also silence an alert’s notifications for a custom duration when you acknowledge the alert (see [**Custom Silence Alert**](/v1/docs/manage-alerts#custom-silence-alert)).

## Alert Debug Dialog

The Alert Debug dialog provides context to understand why an alert was triggered by a policy threshold. Accessible to all user levels, alert types, and states, it’s accessed via the **Debug Alert** button (see [**Alert-Specific Actions**](/v1/docs/alerting-page#alertspecific-actions)).

### Debug Dialog UI

The Debug Alert dialog includes the following UI elements:

- **Title bar**: Displays “Debug [policy type] Alert,” where policy type is Protect, Traffic, Cloud, or NMS.
- **Close**: Click the **X** in the upper right to close the dialog.
- **Policy**: The policy name that triggered the alert (top left).
- **Alert ID**: The unique alert ID (top right).
- **Alert triggers**: The dimensions that triggered the alert (e.g. Dest IP; see [**Alert Summary Drawer**](/v1/docs/alerting-page#alert-details-drawer1)).
- **Lookback**: Use the dropdown to adjust the time range back from the present (between 30 minutes and 15 days).

> [!NOTE]
> **Note**: If the alert was triggered before the start of the selected time range, the start of the range will be adjusted to include the start of the alert.
- **Graph**: A dot chart covering the selected **Lookback** range, with plots as listed in [**Debug Graph**](/v1/docs/alerting-page#debug-graph).

### Debug Graph

The Debug graph is a dot plot for alert data. Hover over a dot to open a popup with a timestamp and additional information, or dim all dots of a different type (e.g., baseline dots dim when hovering over a match).

![Dots representing alert-related events are plotted against the Lookback time range.](https://cdn.us.document360.io/082e25b5-afce-42d4-8f47-70bd3f1d02b7/Images/Documentation/Alrt-Debug_dialog(1).png)The chart includes:

- **Time**: Horizontal axis showing the time range set with the **Lookback** control (see [**Debug Dialog UI**](/v1/docs/alerting-page#debug-dialog-ui)).
- **Values**: Vertical axis with measurement and units determined by the policy dimensions and metrics.
- **Triggering event**: Vertical red line showing the alert trigger time.
- **Matches**: Purple dots representing matches between the evaluated traffic and policy thresholds.
- **Baseline**: Brown dots representing baseline values, if baselining is enabled (see [**Baseline Settings**](/v1/docs/flow-policy-settings#policy-baseline-settings)).
- **Baseline Fallback**: Green dots representing fallback baseline values if baselining is enabled but no baseline exists.
- **Static Threshold**: Horizontal red dashed line representing the policy’s static threshold (see [**Threshold Conditions**](/v1/docs/flow-policy-settings#conditions2)).
- **Policy Min Traffic**: Horizontal purple line representing the minimum traffic threshold (see [**Building Your Dataset**](/v1/docs/flow-policy-settings#advanced-settings1)). Keys with traffic below this amount won't be plotted.
- **Legend**: Combinations of dots and labels showing data types and their colors. Hover over a combination to dim all other data types, or click a combination to dim plots of that type.
