Salem Cyber Doc Site
  • 🏠Documentation Home
  • ✨Initiation Guides
    • Quickstart: Deploy Salem
    • Admin Guide
    • Installing Teams App
    • Installing Browser Extension
    • Feature Overview
  • ✨General Guides
    • Managing Alerts
    • Managing Questions
    • Threat Notification Management
    • Uploading Files
    • Logical Operations
  • ✨Configurations Specification
    • Configuration Home
    • Action Conf
      • "match" ActionConfs
      • "webhook" ActionConfs
      • "llm" ActionConfs
    • Action Definition
      • Azure Log Analytics
      • Microsoft Graph API
      • Splunk Search
      • Bring Your Own LLM
    • Parsing Conf
      • Summary Details
    • Report Conf
    • LLM Configuration
  • 💾Changelog
    • Dec 5th '24: Get cracking on your holiday shopping list
    • July 18th, ’24: Beat the heat and the hackers
    • Apr 17th, '24: Alert showers make analysts sour... no longer with Salem!
    • Mar 5, '24: They're after me (and your) secure systems! We're na-tur-ally suspicious
    • Jan 31, '24: New year, new me... and a new way to extract data from your alerts
    • Dec 21, '23: Jingle bells, WannaCry smells, your escalated alert just laid an egg
    • Nov 14, '23: Stuff the turkey or stuff cyber alerts with context... Why not both?
    • Oct 25, '23: Llama, llama on the wall which alert is scariest of them all
    • Sept 19, '23: Context building via true positive/false positive workflow
    • Sept 1, '23: Alert report UI, webhook actions, and question upgrades
Powered by GitBook
On this page
  • Alert Management
  • Ask Salem to view recent alerts
  • How Salem investigations work
  • Salem Questions
  • Viewing Alert Metrics
  1. General Guides

Managing Alerts

PreviousFeature OverviewNextManaging Questions

Last updated 11 months ago

Use Salem to review recent cyber alerts, identify priority alerts, and provide context to aid Salem in its investigations.

Jump here to see more about how to connect alert data sources to Salem

Salem may forward you alerts it thinks are worth your review. Additionally, you can ask Salem to show you alerts that it is analyzing by first sending Salem a message such as "Hey Salem.: "

When a new cyber alert is provided to Salem, it uses the information available in the alert to understand what kind of threat is being represented. It will then use what it's learned to start adding additional context. As new context is made available, Salem will update its predicted likelihood of whether this alert represents a threat. Salem will ask questions to help it find paths to additional context. By answering Salem's questions, you help it perform better future investigations.

Periodically, Salem may reach out to you to ask you to answer a question. These questions are based on alerts recently received by Salem. Answering these questions improves Salem's ability to identify likely threats.

You can also choose to answer questions by selecting help Salem learn from the main menu card

Salem Menu

You can view alert metrics by asking Salem for the latest alert metrics.

From the metrics card, you'll see the number of questions and answers asked.

From the main card, click "Actions" and then the "Metrics" button.

✨
Viewing Alert Metrics
Adding Alerts to Salem
Alert Management
Ask Salem to view recent alerts
How Salem investigations work
Salem Questions