Basic Parameters
| Parameter | Description |
|---|---|
| Description | The main detailed description and context for the resource. |
| Source | The source system or tool that generated the alert. |
| Source Ref | The unique identifier for this alert within its original source system. |
| Title | A short, descriptive title for the resource. |
| Type | The category or type of the alert. |
Advanced Parameters
| Parameter | Description |
|---|---|
| Assignee | User to assign the alert to. |
| Case Template | A specific case template to apply automatically if this alert is promoted to a case. |
| Custom Fields | Custom fields as an array of objects. For more information about the Custom Fields parameter, visit TheHive API documentation. |
| Date | The timestamp (milliseconds epoch) for when the event occurred. Defaults to the time the alert is created if omitted. |
| External Link | A URL linking back to the alert or event in the source system. |
| Flag | Set to true to visually flag the resource in the user interface for attention. |
| Observables | An array of observable objects related to this alert. |
| PAP | Prioritized Asset Profile, the severity level that is used to indicate the importance of an asset. White: The asset is not critical. Green: The asset is important, but not critical. Amber: The asset is critical. Red: The asset is essential. |
| Procedures | List of procedures (TTPs) to link the alert to. |
| Severity | The severity level of the resource. |
| Status | The status of the resource. |
| Summary | A brief summary of the resource. |
| TLP | Traffic Light Protocol, a set of designations used to ensure that sensitive information is shared with the appropriate audience. CLEAR: unlimited formerly. GREEN: community-wide. AMBER: limited distribution. AMBER+STRICT: restricts sharing to the organization only. RED: personal for named recipients only. |
| Tags | An array of keywords (tags) as strings to categorize the resource. |
Example Output
{
"_createdAt": 1640000000000,
"_createdBy": "string",
"_id": "string",
"_type": "string",
"_updatedAt": 1640000000000,
"_updatedBy": "string",
"assignee": "string",
"caseId": "string",
"caseTemplate": "string",
"closedDate": 1640000000000,
"customFields": [
{
"_id": "string",
"name": "string",
"order": 0,
"type": "string",
"value": ""
}
],
"date": 1640000000000,
"description": "string",
"externalLink": "string",
"extraData": {},
"follow": false,
"importedDate": 1640000000000,
"inProgressDate": 1640000000000,
"newDate": 1640000000000,
"observableCount": 0,
"pap": 0,
"papLabel": "string",
"severity": 0,
"severityLabel": "string",
"source": "string",
"sourceRef": "string",
"stage": "string",
"status": "string",
"summary": "string",
"tags": [
"string"
],
"timeToAcknowledge": 0,
"timeToDetect": 0,
"timeToQualify": 0,
"timeToTriage": 0,
"title": "string",
"tlp": 0,
"tlpLabel": "string",
"type": "string"
}