Detailed Explanation of the Alert Template Table
9.0
, you should refer to this pageName
parameter is selected as a deduplication parameter, it will cancel any other parameter and be used exclusively for the deduplication rule.
%
symbol can be used as a wildcard in alert names. This means that you can substitute %
for any sequence of characters. This allows you to match multiple alert names without needing to specify each one exactly.
*
symbol is used in alert names, it indicates that the deduplication rule must be applied to all alerts that include *
in their name.
device.external_ip
) represents the location of the observable in the alert payload, while the value (e.g., "IP Address"
) specifies the type of observable.frodo@middleearth.com
) from the alert payload and store it as an observable of type User Email.
"User Email"
."sender.emailAddress.name"
) and define the appropriate type (e.g., "User Name"
).