Open routing
Go to Alerts > Triggers & Routing. The page shows:- Alert volume from the last 30 days
- Alert sources
- Open unassigned detection alerts
- Response agents that can handle alerts
- A flow diagram from sources to response agents
- The default route for detection-created alerts
Detection alert routing
Detection-created alerts follow this order:- Use the detection’s override if one exists.
- Otherwise use the organization default response agent.
- If the effective setting is unassigned, create the alert and leave it open.
Set the organization default
- Go to Alerts > Triggers & Routing.
- Find Default alert-handling agent below the flow diagram.
- Choose a response agent, or choose Leave unassigned to keep new detection alerts open.
Override one detection
From the detection itself:- Go to Detection > Detections and open the detection.
- Open the Settings tab.
- Under Routing, open Route alerts to and choose one of:
- Default · agent name to inherit the organization default
- Leave unassigned
- A specific response agent
Trigger-created alerts
Response-agent triggers can create alerts when Create alert on trigger is enabled. Default behavior by trigger type:
You can change the toggle when creating or editing the trigger. Trigger-created alerts are assigned to the response agent that owns the trigger, and Cotool starts that agent’s triage run from the alert.
Cotool stores the original trigger payload with the alert. The alert detail page shows the payload in Alert Payload when it is available.
Routing outcomes
Keep routing healthy
Review Triggers & Routing when:- New detection alerts are piling up as open and unassigned
- A response agent is deleted or disabled
- A detection should be handled by a different response agent than the organization default
- A trigger is producing too many or too few alerts