For better triage and focus, alerts that have a higher priority are brought to the top
of the alert list. This placement brings to your attention those alerts that require you to
handle them at a higher priority than other alerts.
The priority group indicates which alerts should be attended to first. Priority is
calculated for each open alert and
then mapped into one of four priority categories.
Thresholds
Thresholds on the calculated priority
are used to determine to which category the alert is mapped to. Alerts with a priority above
the value of the evt_mgmt.top_priority_group_threshold property are
categorized as Urgent, which is the highest priority. The default value
of this threshold is 1M.
Triggers that cause recalculation
Changes to open alerts trigger the recalculation of the priority and then the alert is
again categorized into the relevant priority group. Closed alerts are not considered for
alert priority group calculation.