Alerts & incidents
The console is where Mobius's work becomes reviewable. Three views matter day to day.
Alerts
Every ingested alert with its L1 decision attached:
- Verdict and risk score, with the analyst rationale one click away. The full decision trail is auditable per alert.
- MITRE ATT&CK technique and tactic chips.
- Filters by environment, verdict, severity, rule, agent, and time.
Use it to answer "what did Mobius decide, and why", and to spot-check verdicts while you tune your trust in automation.
The alert detail
Click any row to open the alert detail. The panel at the bottom groups
everything Wazuh and the AI captured into tabs: Triage history, IoCs,
MITRE, Compliance, the Wazuh categories Rule, Agent, Data and
Decoder / Manager, and raw JSON. Most chips are clickable pivots:
click a MITRE tactic, a rule group, a compliance framework, or a source or
agent IP to jump to the alerts list pre-filtered by that value. MITRE
technique ids link out to attack.mitre.org, and every IoC has a one-click
copy button.
When the alert's environment has a Wazuh Dashboard URL configured, a Go to Wazuh button in the header jumps straight to the exact document, or to its surrounding events, in your own Wazuh Dashboard Discover view, opened with your own dashboard login.
Archive noisy alerts
Tidy the queue by archiving alerts you have handled or consider noise: per row, in bulk, or every alert matching the current filters. Archived alerts drop out of the default view. Flip the Archived filter to archived or all to bring them back. Archiving never deletes data. It only changes what the list shows by default.
Incidents
The first screen an analyst should open: escalations grouped into incidents, ranked by risk, each with its summary, member alerts, timeline, and status. Pending IR approvals surface here and in the bell.
Click any incident to see the underlying alerts, copy affected users and IoCs to the clipboard, change its status, hand it off as a case, or generate a report. Narrow the list with the filter bar: full-text search plus status, severity, category, MITRE tactic and technique, source and agent IP, rule group, and compliance. The last four match the incident's correlated alerts. Click any column header to sort. Filters are reflected in the URL, so a filtered view is shareable.
A status you set stays yours. When new alerts join an incident you already resolved, Mobius does not reopen it: the incident keeps your status and is marked for review, so you decide whether the new activity changes the verdict.
How to read an incident's evidence, verify it, and reach a verdict: Reading an incident.
Environments
Per-environment health: connector session state, a probe per target for the indexer and the Wazuh API, ingest cadence and lag, and processing volume. When something stalls, this page says which half is unhealthy: your side, meaning the connector and the indexer, or the processing side.
Two usage counters ride along per environment:
- Data (30d) is the total data flowing in and out over the last 30 days. Open an environment to see it broken down into four windows, 24h, 7d, 30d and all-time, each with data in against data out and the number of queries. Every query Mobius makes against your Wazuh stack is counted, so nothing slips by.
- LLM (30d) is the total AI tokens spent triaging and investigating that environment's alerts, with the same four windows, each showing input against output tokens and the call count. Analysis that spans several environments is recorded too, but grouped separately since it can't be attributed to one environment.
Each environment card also summarises its ingestion policy: the severity floor, whether manager alerts are ignored, and how many include and exclude rules are active, with the version that is running. Which alerts Mobius fetches in the first place is decided there; see Ingestion policy.
Ingest can be paused per environment, which is useful during maintenance windows or noisy incident storms. Pausing stops new triage, and its cost, without touching the connector.