How-to
Correlated Incidents
When several detectors agree on the same target, Edge groups the alerts into one incident with a confidence score, so you investigate once.
Why incidents exist
One real attack rarely trips one detector. A scraper on a datacentre network can trip the ASN spike, the 499 rate, and the cache bypass detectors at once; a credential-stuffing run can light up a path spike and a probe alert together. Investigated separately, that's three tabs and triple work. Investigated as one incident, it's one story.
How grouping works
When multiple detectors fire on the same target (the same network, or the same network and path) within a short window, Edge links the alerts into an incident. The more independent detectors agree, the higher the incident's confidence: two unrelated signals pointing at the same actor is much stronger evidence than either alone.
Agreement across time counts too: the ASN Recurrence detector flags networks that keep coming back over days and weeks, and when a repeat offender is also tripping a live detector right now, that combination scores very high: a known-bad actor actively doing the bad thing.
What you see
- On any member alert — a banner: this alert is part of an incident, how many detectors agree, and the combined confidence. Click through to the incident.
- On the incident page — an evidence strip summarising the strongest signals across all member alerts (peak rates, worst ratios, paths hit), the full list of member alerts, and the event history.
- One guided response — because the member alerts share a target, the incident page carries a single drafted rule for that target, with the same one-click apply and rollback as an alert (Applying and Rolling Back Protections). Stop the actor once, not per-alert.
How to work an incident
- Read the evidence strip first: it's the "how bad is this" summary.
- Check the member alerts for the earliest one; that's usually the entry point (often a probe or reconnaissance alert preceding the volume).
- Act on the shared target from the incident page rather than from each alert.
- Resolve the member alerts as their conditions clear; most auto-resolve.