CyTech AQUILA - Cyber Incident Management (CIM): Alert Rules

The Alert Rules section provides centralized management of alert rules assigned to various log sources. This module enables administrators and analysts to review, configure, and monitor rules that generate alerts for security and operational events.

image.png

Header Summary
Search and Filter
Integrations (Under Development)
Add Alert Rule

image.png

Alert Rule Listings

image.png

Users can also click the Rule to see more details about the alert rules.

image.png

The users can also Edit Alert Rule by pressing the button. In this section they can adjust the time interval and its risk score or change its severity.

image.png

Manage Alert Rules

The Manage Alert Rules interface provides administrators with a centralized view and management panel for alert rules assigned to a data source. This page allows users to search, filter, review, enable/disable, and monitor the execution of a specific alert rule.

Search and Filter

image.png

Global Toggle Controls

image.png

Rule Table

The central section of the page displays a table containing all AWS alert rules with associated metadata and controls. Each row corresponds to a specific rule, with the following columns:

  1. Rule
    • The rule name is hyperlinked, directing the user to the detailed configuration page for that specific rule
      image.png
  2. Risk Score

    • Numerical value representing the calculated risk impact of the rule if triggered.

      image.png

  3. Last Run
    • Displays the most recent execution time of the rule.

      image.png

  4. Severity
    • Severity levels include:
      • Low (Green)
      • Medium (Yellow)
      • High (Red)

        image.png

  5. Last Response
    • Shows the outcome of the most recent rule execution.
    • Status values include:
      • Succeeded (green indicator)
      • Potential Failed
      • Failed

        image.png


  6. Last Updated
    • Provides the timestamp when the rule was last modified.

      HEHE.png

  7. Enabled/Disabled Toggle
    • Each rule has an individual toggle to enable or disable its monitoring function.
    • Active (enabled) rules are marked in blue, while disabled rules would appear in gray.

      HEHE (2).png

This section ensures visibility into how alerts are defined and enforced across environments. By consolidating rule management, it allows administrators to maintain consistency, identify gaps, and prioritize responses effectively.

Please refer to the document from the previous sub-module: CyTech AQUILA - Cyber Incident Management (CIM): Reports

Please refer to the document for the next sub-module: CyTech AQUILA - Cyber Incident Management (CIM): Settings

If you need further assistance, kindly contact our support at support@cytechint.com for prompt assistance and guidance.


Revision #6
Created 13 February 2026 02:21:49
Updated 17 April 2026 03:30:24