> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Alarms List Columns

<Icon icon="users" iconType="solid" /> Role Availability | ✔️ Read-Only ✔️ Analyst ✔️ Manager

For each alarm in the alarm in the List view, USM Central displays useful information to help you determine the best response.

The following table lists the fields you see on the page.

**List of the Default Columns in Alarms**

| Column / Field Name | Description                                                                                                                                                                                                                                                                                        |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Intent              | Describes the attack pattern of indicators intruding on your system.                                                                                                                                                                                                                               |
| Strategy            | Type of attack.                                                                                                                                                                                                                                                                                    |
| Method              | If known, the method of attack or infiltration associated with the indicator that generated the alarm.                                                                                                                                                                                             |
| Deployment          | Name of the <Tooltip tip="Entire process involved in installation, configuration, startup, and testing of hardware and software in a specific environment.">deployment</Tooltip> on which the alarm has been triggered.                                                                            |
| Time Created        | The date and time of the creation of the alarm. The displayed date depends on your computer's time zone.                                                                                                                                                                                           |
| OTX                 | Indicates whether it is an LevelBlue Labs™ Open Threat Exchange® (OTX™) alarm. If the icon is active, click it to go the [OTX site](https://otx.alienvault.com/).                                                                                                                                  |
| Sources             | <Tooltip tip="A hostname is a label that is assigned to a device connected to a computer network and is used to identify the device on the network.">Hostname</Tooltip> or IP address of the source (including a national flag icon if the country is known) for an event creating the alarm.      |
| Destinations        | Hostname or IP address of the destination (including a national flag icon if the country is known) that received the events generating the alarm.                                                                                                                                                  |
| Alarm Status        | Status applied to the alarm. By default, it can be Open, In Review, and Closed. See [Alarm Status](/documentation/usm-central/alarms/alarm-status) for more information. The alarms that have the status "Closed" are not displayed in the list.                                                   |
| Labels              | Labels applied to the alarm. By default, it can be In Progress, False Positive, Open, and Closed. You can create and manage labels. See [Labeling the Alarms](/documentation/usm-central/alarms/labeling-alarms) for more information.                                                             |
| Sensors             | The <Tooltip tip="Sensors are deployed into an on-premises, cloud, or multi-cloud environment to collect logs and other security-related data. This data is normalized and then securely forwarded to USM Anywhere for analysis and correlation.">sensor</Tooltip> name associated with the alarm. |
| Priority            | Impact of the detected attack. It can be Low, Medium, or High. See [Priority Field for Alarms](/documentation/usm-central/alarms/alarms-list-priority-field) for more information.                                                                                                                 |

From the list of alarms, you can click any individual alarm row to display more information on the selected alarm, including individual events that triggered the alarm. See [View Alarm Details](/documentation/usm-central/alarms/view-alarms-details) for more information.

To select an alarm, select the checkbox to the left of the alarm. You can select all alarms at the same time by selecting the first checkbox in the column. These buttons display when you select an alarm:

* **Remove Alarm Labels**: This button displays if there are labels associated to any alarm. Use this button to remove a label or labels from an alarm. See [Labeling the Alarms](/documentation/usm-central/alarms/labeling-alarms) for more information.
* **Apply Labels**: You can add a label to an alarm, which enables you to have classified alarms. See [Labeling the Alarms](/documentation/usm-central/alarms/labeling-alarms) for more information.
* **Alarm Status**: You can add a status to an alarm. See [Alarm Status](/documentation/usm-central/alarms/alarm-status) for more information.

<Frame>
  <img src="https://mintcdn.com/levelblue-5324744e/o6MmmgEHGgnNzkz0/images/usm-central/alarmslistview.webp?fit=max&auto=format&n=o6MmmgEHGgnNzkz0&q=85&s=69d038ad58e488c3cfb968a0d24279ce" alt="" width="989" height="231" data-path="images/usm-central/alarmslistview.webp" />
</Frame>

To distinguish between label and status, see [Differences between Statuses and Labels](/documentation/usm-central/alarms/alarm-status#diffStatusLabel).

The asset name includes a chevron icon that can be gray (<img src="https://mintcdn.com/levelblue-5324744e/yWllrh2N4cA-lI7S/images/usm-central/angle-down.svg?fit=max&auto=format&n=yWllrh2N4cA-lI7S&q=85&s=7630d461b9e824290740906b7be9ab0d" className="inline m-0" width="20" height="20" data-path="images/usm-central/angle-down.svg" />) if the asset is not in the system, or blue (<img src="https://mintcdn.com/levelblue-5324744e/yWllrh2N4cA-lI7S/images/usm-central/chevron-down.svg?fit=max&auto=format&n=yWllrh2N4cA-lI7S&q=85&s=0c9355b21a7f325e30a052e25a483271" className="inline m-0" width="20" height="20" data-path="images/usm-central/chevron-down.svg" />) if the asset has been added to the system.

Click the gray chevron icon (<img src="https://mintcdn.com/levelblue-5324744e/yWllrh2N4cA-lI7S/images/usm-central/angle-down.svg?fit=max&auto=format&n=yWllrh2N4cA-lI7S&q=85&s=7630d461b9e824290740906b7be9ab0d" className="inline m-0" width="20" height="20" data-path="images/usm-central/angle-down.svg" />) to access these options:

* Add to current filter: Use this option to add the asset name as a search filter. See [Searching Events](/documentation/usm-anywhere/user-guide/events/searching-events) for more information.
* Look up in OTX: This option searches the IP address of the source asset in the LevelBlue LevelBlue Labs Open Threat Exchange® (OTX™) page. See [Using OTX in USM Anywhere](/documentation/usm-anywhere/user-guide/otx/using-otx-in-anywhere) for more information.

Click the blue chevron icon (<img src="https://mintcdn.com/levelblue-5324744e/yWllrh2N4cA-lI7S/images/usm-central/chevron-down.svg?fit=max&auto=format&n=yWllrh2N4cA-lI7S&q=85&s=0c9355b21a7f325e30a052e25a483271" className="inline m-0" width="20" height="20" data-path="images/usm-central/chevron-down.svg" />) to access these options:

* Add to current filter: Use this option to add the asset name as a search filter.
* Look up in OTX: This option searches the IP address of the asset in the LevelBlue LevelBlue Labs Open Threat Exchange® (OTX™) page. See [Using OTX in USM Anywhere](/documentation/usm-anywhere/user-guide/otx/using-otx-in-anywhere) for more information.
* Full Details: See [Viewing Assets Details](/documentation/usm-anywhere/user-guide/asset-management/asset-administration/viewing-asset-details) for more information.

You can configure the view you want for the list of alarms. See [Alarms Views](/documentation/usm-central/alarms/views) for more information.

Click Generate Report to open the Configure Report dialog box. See [Create an Alarms Report](/documentation/usm-central/alarms/exporting-alarms) for more details.

Click the <img src="https://mintcdn.com/levelblue-5324744e/jjwNP9y3XfeZH19Z/images/usm-central/line-chart.svg?fit=max&auto=format&n=jjwNP9y3XfeZH19Z&q=85&s=4e4596a1002c5456ccb68eb0570b101d" className="inline m-0" width="24" height="24" data-path="images/usm-central/line-chart.svg" /> icon to change the graph to a Count/Time or Alarms by Intent view. See [Alarms List View](/documentation/usm-central/alarms/alarms-list-view) for more information.

Click the <img src="https://mintcdn.com/levelblue-5324744e/ZS7tUvuIZXE1ELcm/images/usm-central/star.svg?fit=max&auto=format&n=ZS7tUvuIZXE1ELcm&q=85&s=d70bbccd8d590bc37f56778d4167c1cd" className="inline m-0" width="20" height="20" data-path="images/usm-central/star.svg" /> icon to bookmark an item for quick access.

<Note>
  You can view your bookmarked items by going to the secondary menu and clicking the <img src="https://mintcdn.com/levelblue-5324744e/ZS7tUvuIZXE1ELcm/images/usm-central/star.svg?fit=max&auto=format&n=ZS7tUvuIZXE1ELcm&q=85&s=d70bbccd8d590bc37f56778d4167c1cd" className="inline m-0" width="20" height="20" data-path="images/usm-central/star.svg" /> icon. This will display all of your bookmarked items and provide direct links to each of them.
</Note>

Click the <img src="https://mintcdn.com/levelblue-5324744e/ZS7tUvuIZXE1ELcm/images/usm-central/filter.svg?fit=max&auto=format&n=ZS7tUvuIZXE1ELcm&q=85&s=fa98e2bed0c028eb545c5438fb875e1b" className="inline m-0" width="20" height="20" data-path="images/usm-central/filter.svg" /> icon to filter your search by row fields. See [Searching Alarms](/documentation/usm-central/alarms/searching-alarms) for more information.

You can choose the number of items to display by selecting **20**, **50**, or **100** below the table. You can classify some columns by clicking the icons to the right side of the heading. You can sort the item information in ascending or descending order.
