Skip to main content

Create Alert

Create a new alert and add it to a Case by filling in the following parameters:

Mapping Alert Severity to Blink’s System

Different security tools often report severity using their own scales—numeric values, labels, or custom levels. To ensure consistent prioritization in Blink, you can map these varying severity values, in the advanced settings of the Create Alert action, to Blink’s standardized severity levels (Low=1, Medium=2, High=3, Critical=4). For Example: Example Payload:
In the Severity Parameter: The incoming alert payload specifies a severity of 50.
In Advanced Settings: A severity value of 50 is mapped to Blink’s High severity level, which corresponds to a severity rank of 3 in the output. You can customize these mappings to ensure external alert severity levels align with your internal triage and prioritization standards.
Blink’s severity levels are ranked as:
  • Low = 1
  • Medium = 2
  • High = 3
  • Critical = 4

Delete Alert

Deleting an Alert from a Case by filling in the following parameters in the step.

Update Alert

Updating an already existing Alert in a Case by filling in the following parameters in the step. This action overwrites all of the alert’s data.
If the “Alert Event Lock” setting is enabled in Case Management Settings, the “Update Alert” action will fail. To successfully run this action, you must first disable the setting.