The type of the collection which will indicate which other fields are relevant. For example, detection finding collections will populate the detection field. Findings that evolve into investigations will populate the investigation field.
| Enums | |
|---|---|
| COLLECTION_TYPE_UNSPECIFIED | An unspecified collection type. | 
| TELEMETRY_ALERT | An alert reported in customer telemetry. | 
| GCTI_FINDING | A finding from the Uppercase team. | 
| UPPERCASE_ALERT | |
| RULE_DETECTION | A detection found by applying a rule. | 
| MACHINE_INTELLIGENCE_ALERT | An alert generated by Chronicle machine learning models. | 
| SOAR_ALERT | An alert coming from other SIEMs via Chronicle SOAR. |