Trinetri logo
EndpointOps

Alerts and Notifications

Learn how to review existing alerts by module and severity, and create a new alert rule that fires when an endpoint's metric (like CPU or memory utilization) crosses a threshold you define.

  • 1 min
  • July 28, 2026

What You'll Learn

  • How to review existing alerts, filtered by module and severity
  • How to create a new alert configuration with a metric-based condition
  • How severity levels and status apply to an alert rule
  • How to scope an alert to all endpoints or a specific set
  • How to switch between timeline, list, and card views of triggered alerts
CTA background

Experience Trinetri Autonomous Platform in Action.

Frequently Asked Questions

What defines when an alert fires? An alert configuration pairs an Attribute (such as CPU Utilization % or Authentication Failed) with a Condition (such as GreaterThan or GreaterThanEqual) and a Value. When a scoped endpoint's metric crosses that condition, the alert fires at the configured Severity.
Can an alert apply to only some endpoints? Yes. The Scope setting under an alert configuration supports applying to all endpoints or selecting specific ones, so a rule doesn't have to be fleet-wide.
What severity levels are available? Critical, High, Medium, and Low. Each alert configuration is assigned one of these levels, and the alerts list can be filtered by severity to focus on what matters most.
What's the difference between a CLEAR and CRITICAL state on the same alert? The same policy (for example, a CPU Policy or Memory Policy) can show CLEAR when the metric is back under threshold and CRITICAL when it's currently breached, so the alert list reflects the endpoint's live state rather than a one-time notification.
Can I toggle an alert configuration off without deleting it? Yes. Each alert configuration has a Status toggle, so a rule can be disabled temporarily without removing its definition.