Example: Set a timer to run enrichment actions
Suppose you want to automatically raise the severity and change the owner of all the unassigned Major events, after a duration of 6 hours has lapsed.
Actions involved: Timeout, If-Then-Else, Enrich
Event selection criteria: Define a condition to select all the events.
The following image illustrates how the event selection criteria will look.
Build the policy workflow:
- Add the Timeout action. Under the Timeout Settings, define the duration and the unit.
- Add the If action. Under the If Settings, define a condition to check unassigned events with the status, Major.
- Under Then, add an Enrich action to change the event severity to Critical.
- Under the previous action, add an Enrich action to change the owner to Admin.
Final workflow: The following image illustrates how the policy workflow will look.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*