---
title: Understand Event Severity
slug: understand-event-severity
description: Learn how Flare, a powerful security tool, assigns severity levels to activities based on personal information and login credentials. This prioritization helps users filter events, with options to adjust severity thresholds for identifiers and search resu
docTags: 
createdAt: 2023-10-03T16:53:40.496Z
---

Every Activity in Flare is given a **Severity**, based on our analysis of the content. For example, Activities containing personal information or login credentials will have a higher Severity. We are constantly working to refine our measuring methods so the severity is not always a perfect representation of the risk level for an individual Event. Instead, it is meant as a way to prioritize Events as a whole.

When defining an Identifier, the severity is used to eliminate any events that have a severity level lower than a specific threshold. To update your current settings, browse to the Identifiers page, edit each one, and set the desired threshold. We recommend keeping the threshold low for identifiers that generally produce high-quality results, such as looking for a domain name on the dark web, and increasing the threshold for more noisy items, such as a common brand name on Github.

Similarly, it is possible to change the severity threshold for search results or when viewing feeds to expand or narrow the results based on severity.

Details on the severity process are described in the various source pages.

# Severity descriptions

<font color="#adc3fa">﻿⬤ </font> **INFO&#x9;**&#x56;alidated not-sensitive

Ex. Domain Lists

<font color="#fae158">⬤</font> **LOW&#x20;**&#x50;ublic information

Ex. Github content, pastes

<font color="#efc342">⬤ </font>**MEDIUM&#x20;**&#x50;otentially sensitive based on source or query

Ex. Illicit network mentions, Github secrets, Google dorks

<font color="#ef8b42">⬤ </font>**HIGH&#x20;**&#x50;otential leaked data or threat identified

Ex. PII, config files, credentials (Leaked Data)

<font color="#ea364d">⬤ </font>**CRITICAL&#x20;**&#x50;otential serious leaked data or threat identified

# Scoring and Integrations

When using some Integrations (or when using Flare's API), scoring might be communicated with a numerical value instead of the labels listed above. The following list details the numerical values you may receive and their corresponding severities:

1 = <font color="#adc3fa">⬤ </font> **INFO&#x9;**

2 = <font color="#fae158">⬤</font> **LOW**

3 = <font color="#efc342">⬤ </font>**MEDIUM**

4 = <font color="#ef8b42">⬤ </font>**HIGH**

5 = <font color="#ea364d">⬤ </font>**CRITICAL**

# Related Articles

:::CtaButton{label="Open Ports" docId="UnTx1JmVf2LSapPaMBYJ2" openInNewTab="true"}

:::

:::CtaButton{label="Respond to Open Web Alerts" docId="l6oGozZyuHkB-BcPgui-T" openInNewTab="true"}

:::

:::CtaButton{label="Respond to Illicit Networks" docId="ANbv4gPYVbB7DqBHaJYoe" openInNewTab="true"}

:::

