Example: Add operation note for event assignment
To add notes to incoming events, perform the following steps:
Actions used in the example
- Enrich
- Function
For more information about actions, see Actions-for-advanced-and-time-based-enrichment.
To define the event selection criteria
- Select Configuration > Event Policies and click Create.
- In the Event Selection Criteria, define a condition to select open events that contain the message "Filesystem available space < 1000 MB".
The following image illustrates how the event selection criteria will look.
To learn how to construct the event selection criteria, see Creating-and-enabling-event-policies.
To build the policy workflow
On the Advanced Enrichment page, perform the following steps to build the policy workflow:
- Add an Enrich action to enrich the event status to Assigned.
- Add another Enrich action to assign an owner for the event.
- Add a Function action to add an operation note for event assignment.
Results
The resulting policy workflow adds an operation note for event assignment as shown in the following image:
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*