Create Alert Action Fields
Parameter | Description |
---|---|
Name | The name of the Alert |
Vendor | The Vendor associated with the alert |
Event | The Alert Event |
Severity | This is the severity rank of your Case. If you dont want use the built in severity levels, you can map severity values from an incoming alert payloads to Blink’s system severity levels (e.g., ‘10’ → ‘Low’). Use the mapping settings in Advanced Settings. |
Link Cased | The Name and ID of the Case you want to add to this Alert to |
Description | A brief explanation explaining the Alert |
Custom Fields (JSON Format) | Add a Custom Field in JSON format. Please note that this applies only if you have manually added a custom record column to the subject table. |
Advanced- Dedup Table | The selected table to evaluate the duplicated condition (Dedup Condition)against. |
Advanced- Dedup Condition | The duplicate condition to check whether to insert the record or not. When the condition is met, the record will not be inserted. |
Advanced- Linked Observables | The Name and ID of the Observable you want to link to this Alert |
Advanced- Linked Alerts | The Name and ID of the Alert you want to link to this Alert. |
Advanced- Linked Attachments | The Name and ID of the Attachment you want to link to this Alert. |
Advanced- Linked Tasks | The Name and ID of the Tasks you want to link to this Alert. |
Advanced- Default Severity | Default severity for un-resolved severities. |
Advanced- Low Severity Mapping | A comma-separated list of vendor-specific severity values that map to Blink’s Case Management’s Low severity level. |
Advanced- Medium Severity Mapping | A comma-separated list of vendor-specific severity values that map to Blink’s Case Management’s Medium severity level. |
Advanced- High Severity Mapping | A comma-separated list of vendor-specific severity values that map to Blink’s Case Management’s High severity level. |
Advanced- Critical Severity Mapping | A comma-separated list of vendor-specific severity values that map to Blink’s Case Management’s Critical severity level. |
50
.
50
is mapped to Blink’s High severity level, which corresponds to a severity rank of 3
in the output.You can customize these mappings to ensure external alert severity levels align with your internal triage and prioritization standards.
1
2
3
4
name
, event
, and severity
, vendor
etc. See Create Alert Action Fields table for all fields extracted.