Immediate Actions:
- Review the alert details (IP, timestamp, event type)
- Log into the Security Events Dashboard
- Verify the IP has been automatically blocked
- Check for related events from the same IP or pattern
- Document the incident
- Monitor for additional attacks
- Consider blocking related IPs if you see coordinated attacks