---
title: "Review and dismiss machine events"
description: "Read the Event Alerts list on a machine's Health tab: what an event is and how it differs from the rule that fired it, the severity and type filter pills, how rows are grouped by age and sorted, dismissing one event or a whole time group, and the two ways an event becomes a work order."
category: "Machine health"
source_url: "https://www.iotflows.com/docs/monitoring/asset-events/"
---
# Review and dismiss machine events

The event feed for one machine, and what to do with what it flags.

An *event* is the record IoTFlows writes when an alert rule on this machine fires: a health score falling past 60%, a stop longer than your downtime threshold, a shock above the sensor's g limit. The rule decides when that happens and who gets told. The event is what the rule leaves behind, and the **Event Alerts** list on the Health tab is where you read it.

**Prerequisites.** A SenseAi or SenseAi Embedded asset on firmware 5 or later, see [Monitor machine health and vibration](/docs/monitoring/machine-health/). At least one event type enabled on the machine, see [Set alert rules for a machine](/docs/alerts/asset-event-rules/).

## Open the event list
1. Open the machine's page at `/assets/selected-asset/:id`.
2. Click **Health** in the tab strip under the header.
3. In the right column of the **Machine Health Summary** card, click **Alerts**.

That column holds two tabs, each with its own count: **Alerts**, the events, and **Notes**, the comments people have left on this machine's charts. The chip beside the **Event Alerts** heading repeats the total.

The list ignores the time range buttons at the top of the tab. Moving from **7d** to **90d** redraws every chart and leaves the list alone, because it is not a window: it is every event on this machine that nobody has dismissed yet. To *dismiss* an event is to mark it handled, which takes it off this list.

With nothing outstanding, the card reads **No Active Alerts**, over **All systems operating normally**.

![The Event Alerts column on the Health tab. Alerts and Notes tabs sit at the top with counts, then a heading reading EVENT ALERTS with an 8 total chip, then two rows of filter pills for Severity and Type. Below them three events from the last hour are drawn flat, then a group header reading LAST 24 HOURS with a count chip of 5 sits over a collapsed stack of cards. Each row carries a type icon, a title, a colored value pill, a relative time such as 22m ago, a one-line message and a Dismiss link](/images/monitoring/mon-events-01.webp)

*The event list for one machine. Each row is a rule that fired.*

## Filter by severity and type
Two rows of pills sit above the list. **Severity** offers **All**, **Critical**, **Warning** and **Caution**, and **Type** offers **All**, **Health**, **Temp**, **Machine** and **Shock**. The two combine, so **Critical** plus **Temp** shows only critical temperature events.

The number on each pill counts the whole list, not what the other row leaves. **Critical (4)** still reads 4 with **Health** selected, even when only one of those four critical events is a health event.

**Device Offline events count as Machine.** Type is read from the event type's own name, and a lost connection carries none of the four, so it falls in with **Machine Down** and **Machine Up**.

Filter before you clear anything. The bulk action described in [Dismiss a whole group](#dismiss-all) acts on what the filters leave visible, which makes "clear every caution and keep the criticals" two clicks.

![A cropped detail of the two filter rows. The Severity row shows All, Critical, Warning and Caution pills with counts in parentheses, with Critical selected and filled red. The Type row below shows All, Health, Temp, Machine and Shock pills with counts, with All selected. Callout 1 marks the severity row and callout 2 marks the type row](/images/monitoring/mon-events-02.webp)

*Filtering the feed by severity and event type.*

## Read an event
Every row carries the same six things:

- A type icon: a heart for health, a thermometer for temperature, a falling clock for machine status, a waveform for shock.
- The event title, for example **Warning Health Alert** or **Machine Down**.
- The measured value, in a pill colored by severity, with the unit the event type implies: `%` for a health score, `°C` for temperature, `G` for shock, `min` for a stop.
- How long ago it fired, written as `22m ago`, `6h ago`, `Yesterday` or `3d ago`.
- The one-line message the event type carries.
- A **Dismiss** link.

Rows are grouped by age under **Last 15 min**, **Last hour**, **Last 6 hours**, **Last 24 hours** and **Older**. A group with no events is not drawn at all. Inside a group, critical sorts above warning above caution, and newer above older within one severity.

A group of three events or fewer is drawn flat. A group with more than three collapses into a stack of three cards under a header carrying the count. Click the header to expand it.

Click a row to line every chart on the tab up on the moment the event fired, and a panel headed **Existing at this time** lists the notes and events within five minutes of it. In a collapsed stack the first click expands the group instead, so expand the group, then click the row. See [the timestamp inspector](/docs/monitoring/machine-health/#inspector).

> **Warning:**
> **Why does a temperature event read °C when I set the rule in °F?** The value pill is always Celsius. The threshold on the rule follows your unit preference, the event does not.

### Event severities
| Severity | Color | Typically from |
|---|---|---|
| **Critical** | Red | **Critical Health Alert**, which fires below 20%. **Critical Temperature**. **Machine Down** at its critical threshold |
| **Warning** | Amber | **Warning Health Alert**, which fires below 40%. **Warning Temperature**. **Machine Down** at its warning threshold |
| **Caution** | Yellow | **Caution Health Alert**, which fires below 60%. Also the fallback: an event arriving with no severity of its own is shown as a caution |

Severity belongs to the event type, not to the event, so you cannot raise or lower one row. It sets the row's color, its position in the group, and which severity pill counts it. Which event types exist and what each one fires on is in [Event types reference](/docs/alerts/event-types-reference/).

## Dismiss one event
Click **Dismiss** at the right of the row. The row leaves immediately and a toast reads **Event has been dismissed**.

Dismissing sets a flag on the event rather than deleting it, so the record survives. No view in the dashboard shows dismissed events, so treat dismissal as the end of your involvement with that row, not as a way to find it again next week.

**Dismiss an event when you have decided about it, not to clear the list.** Clearing the list unread every morning trains everyone to skip the next one, and the next one is the bearing that gave four weeks of warning.

## Dismiss a whole group
**Dismiss All** appears on a group's header, and only on a group holding more than three events. A group of three or fewer has no header, so those rows are dismissed one at a time.

1. Set the severity and type filters to the events you mean to clear.
2. Click the group header, for example **Last 24 hours**, to expand it.
3. Click **Dismiss All**.

It dismisses the events the filters leave visible in that group, not the whole list. With **Caution** selected, the criticals in the same group stay. A toast reports the count, for example `12 events dismissed`.

Use **Dismiss All** on a group that is one incident repeated: forty shock events from one crash, or a run of **Machine Down** rows from a shift everybody already knows about. Dismiss one at a time when the group is mixed, because one bulk click takes the row you had not read yet along with the thirty-nine you had.

![An expanded time group in the event list. The header reads LAST 24 HOURS with a count chip of 5, a chevron, a red Dismiss All button ringed by a violet highlight, and a Collapse button. Five event rows are listed below it, each with its own Dismiss link](/images/monitoring/mon-events-03.webp)

*Dismiss All clears one time group, and only the events the filters leave visible.*

## Turn an event into work
No button on an event row opens a work order. Two routes exist instead, and they answer different questions.

**Have the rule open it.** Every event type on a machine carries a **Work Order** column in **Event Notifications**, with a member to assign the work order to. Turn it on and each event of that type arrives on the maintenance board with nobody having to notice it. Set this up in [Set alert rules for a machine](/docs/alerts/asset-event-rules/).

**Open one yourself.** For an event you read and decided about, raise the work order by hand so you can write what you actually saw into it, see [Create a work order](/docs/maintain/create-a-work-order/).

You do not need the automatic work order on every event type. Turn it on for events with one obvious response, such as a critical health alert. Leave it off for **Machine Down** and **Device Offline**, which fire often and usually mean a person, a jam or a network, not a repair.

## Errors
| Symptom | Cause | Do this |
|---|---|---|
| **Failed to dismiss event** | The dismissal did not save, and the row comes back when the list reloads | Retry. The event is unchanged |
| **Failed to dismiss events** | The same, for **Dismiss All**. None of the group was dismissed | Retry, or dismiss the rows one at a time |
| The list is empty while the machine is clearly in trouble | No event type is enabled for what is happening, or the event type is enabled to notify but not to log | Open **Event Notifications** and check the rule and its **Log** switch, see [Set alert rules for a machine](/docs/alerts/asset-event-rules/) |
| No **Alerts** card anywhere on the tab | The asset is on firmware below 5 and shows the legacy health view | Ask IoTFlows to update the device, see [Get support](/docs/get-started/get-support/) |
| A BeamTracker machine has no list at all | A BeamTracker has no **Health** tab, and the list lives on that tab | Read its events from the notifications they send. See [Set alert rules for a machine](/docs/alerts/asset-event-rules/) |

## See also
- [Set alert rules for a machine](/docs/alerts/asset-event-rules/)
- [Monitor machine health and vibration](/docs/monitoring/machine-health/)
- [Create a work order](/docs/maintain/create-a-work-order/)
- [Event types reference](/docs/alerts/event-types-reference/)
