JSON representation |
---|
{ "id": string, "type": enum ( |
Fields | |
---|---|
id |
|
type |
|
id_namespace |
|
created_time |
A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: |
last_updated_time |
A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: |
time_window |
|
collection_elements[] |
|
detection[] |
|
detection_time |
A timestamp in RFC3339 UTC "Zulu" format, with nanosecond resolution and up to nine fractional digits. Examples: |
investigation |
|
tags[] |
|
response_platform_info |
|
case_name |
|
feedback_summary |
|
feedback_history[] |
|
soar_alert |
|
soar_alert_metadata |
|
data_access_scope |
|
Element
JSON representation |
---|
{ "association": { object ( |
Fields | |
---|---|
association |
|
references[] |
|
label |
|
references_sampled |
|
Reference
JSON representation |
---|
{ "event": { object ( |
Fields | |
---|---|
event |
|
entity |
|
id |
|
ResponsePlatformInfo
JSON representation |
---|
{
"alert_id": string,
"response_platform_type": enum ( |
Fields | |
---|---|
alert_id |
|
response_platform_type |
|
ResponsePlatformType
Enums | |
---|---|
RESPONSE_PLATFORM_TYPE_UNSPECIFIED |
|
RESPONSE_PLATFORM_TYPE_SIEMPLIFY |
SoarAlertMetadata
JSON representation |
---|
{ "alert_id": string, "source_rule": string, "vendor": string, "source_system": string, "product": string, "source_system_ticket_id": string, "source_system_uri": string } |
Fields | |
---|---|
alert_id |
|
source_rule |
|
vendor |
|
source_system |
|
product |
|
source_system_ticket_id |
|
source_system_uri |
|