Example: Drop duplicate events and update the existing event with new severity
To drop duplicate events and enrich the event severity, perform the following steps:
Actions involved
- Lookup
- Function
- Enrich
To define the event selection criteria
- Select Configuration > Event Policies and click Create.
- In the Event Selection Criteria, define a condition to select events from the third-party application (with the custom event class).
The following image illustrates how the event selection criteria will look.
To build the policy workflow
On the Advanced Enrichment page, perform the following steps to build the policy workflow:
- Add the Lookup action. Under the Lookup Settings, select With duplicate events.
- Under Update new event, add the Function action to drop incoming duplicate events.
- Under Update old events, add an Enrich action to update the event severity.
Results
The resulting policy workflow drops duplicate events and enriches the event severity as shown in the following image:
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*