Skip to content

The consolidated view

The AlertKick dashboard is built around one assumption: when something is wrong, the on-call wants to know what, where, and who is handling it, without opening five tabs. This guide walks through the layout and explains what each panel is telling you.

Servers, alerts, security events, and on-call status on one screen

The consolidated view is AlertKick’s central dashboard. It removes the need to switch between separate tools for infrastructure health, alert management, and security monitoring, and puts the answers to the questions that matter during an incident on one screen:

  • Server status - every monitored server at a glance
  • Alert assignment - who is responsible for each alert
  • Escalation status - how far each alert has climbed its escalation chain
  • On-call status - who is currently on the hook
  • Real-time updates - alert status changes appear as they happen

Across the top of every page are four counters: servers, active alerts, security events (24h), and on-call. The numbers are colour-coded so a glance is enough - red means something needs attention, green means quiet. Click any of them to jump to the filtered list.

The default view groups servers by status:

  • Online - agent has checked in within the last 60 seconds
  • Stale - last check-in 1-10 minutes ago
  • Offline - no check-in for more than 10 minutes
  • Pending - agent registered but has not reported yet

Each row carries the hostname, vendor (Ubuntu, Debian, Rocky, Alpine and so on), agent version, and a quick-status chip for each enabled check (CPU, memory, disk, docker, eBPF). Hover the chip to see the current value; click the hostname to open the server detail page with full graphs and event history.

Alerts are grouped by host and then by check, so the same disk-full event across three servers reads as three lines rather than thirty. Each alert shows:

  • The check that triggered it and its current value
  • Its status - open, acknowledged, or resolved
  • How long it has been firing
  • The escalation level it has reached (see escalation policies)
  • Who is currently on the hook for it

Click an alert to open the detail page with the full escalation timeline, assignment history, and action buttons.

The security panel surfaces only events that the AI verdict ranked above info. The full firehose is one click away, but the dashboard keeps it focused on what the on-call needs to act on - critical, high, and unverified events that have not been triaged yet. MITRE ATT&CK tactic chips appear next to each event (see the MITRE ATT&CK overview).

  • Per-metric graphs - these live on the server detail page, not on the overview. Tens of small graphs at the top level mostly add noise.
  • Compliance score trend - moves slowly enough that a daily email is more useful than a dashboard tile.
  • Long historical alert lists - only the active ones are shown here; the search page is for digging into resolved history.
  • Use the Acknowledge button to silence further escalation while you investigate. Acknowledgement is recorded with your name and the time, and shows up on the alert’s audit trail.
  • The dashboard auto-refreshes every 10 seconds. If you need a fixed snapshot for a screenshot, click the pause icon in the top right.
  • The layout is responsive. Mobile and tablet layouts collapse the side panels into bottom tabs so the same four counters and the active alerts list are one tap away.

Dashboard not loading

  • Check browser compatibility and clear the browser cache
  • Verify network connectivity
  • Contact support if the problem persists

Missing alerts

  • Check the active filters
  • Verify the server’s agent is checking in (see the Servers panel)
  • Review the alert’s configuration and the user’s permissions

Need help with the consolidated view? Contact support at support [at] alertkick [dot] com.