Skip to content

Signals

Signals is a security- and monitoring-focused inbox that keeps repetitive alerts out of the main ticket queue without losing visibility or history.

Configure sources

Route notifications from security, identity, endpoint, backup, server, storage, network, and monitoring systems to the configured Signals address. Create source tags so staff can filter alerts by originating system.

Triage decisions

  • Acknowledge: the alert is real and has been seen, but no additional work is required.
  • Dismiss: the alert is a false positive or otherwise not actionable. Add the rationale for future reviewers.
  • Convert to Ticket: create assigned operational work from the Signal.
  • Convert to Incident: promote a security event into the Incident Log.

Automation rules

Create rules that match sender, subject, description, or other supported criteria and then auto-acknowledge, auto-convert to ticket, or auto-convert to incident. Review and refine rules when a match is too broad or too narrow. Automated items remain available historically even when they no longer clutter the active view.

IP lookup and Brief Me

Lookup IPs extracts public IP addresses from a Signal and displays reputation and network context, including risk information, country, ASN, and existing abuse reports when available. Brief Me summarizes key facts, rationale, urgency, and possible next steps.

Video 10: Signals — Watch on YouTube