What the four buckets are telling you
Every event lands in the feed with a severity and a status. You never have to decide which bucket an event belongs to, because the bucket is the first thing it gets, and the total is always the four added up:
- Gateway and VPN
- Certificates and TLS
- Endpoint protection
- Compliance
Four buckets, because those are what break. A spike in the total says which of the four to open, which is the whole reason the total is split at all.
Alert volume is counted at 24 hours, 5 days and 90 days, and events are kept 90 days.