Knowledge base
Your knowledge base is free-form context you write in your own words, so L1 triage reasons with what only you know about your estate. Before an alert is classified, Mobius selects the entries most relevant to it and gives them to the analysis.
Think of the facts a new analyst would need on day one: what a host does, who owns it, which maintenance windows are normal.
Write an entry
Open the knowledge page in the console and use the New knowledge entry form: a short title, the content in plain language, then Create entry. There is no template, and a sentence or a short paragraph is enough.
Pick a scope
- An Organization entry applies to every environment of your tenant. For example, we are a hospital, and patient-data hosts are the crown jewels.
- An Environment entry applies to one environment only. For example, bkp-01 runs the nightly backup at 02:00, so heavy disk and network use then is expected.
Triage always reads your organization entries plus the ones for the alert's own environment.
Wait for Embedded
After you save, the status chip shows Pending embed for a moment while Mobius indexes the entry so triage can find it, then flips to Embedded. Only an Embedded entry can be retrieved. Editing the content re-indexes it automatically. If an entry shows Embed failed, use Re-embed to retry.
See what triage would use
On any alert, the Context considered by triage panel lists the knowledge entries in scope for it. It is a preview of what is available to triage, not a record of what triage actually read: the panel shows everything in scope, while triage picks the entries closest to the alert.
Any member of your team, admin or user, can author knowledge. Entries are private to your tenant.
For patterns you have already investigated and want handled automatically, use known behavior rules instead. A rule can close a match at no cost, where knowledge only informs the model's judgement.