Example: Set a timer to run enrichment actions
To set a timer, perform the following steps:
Actions involved
- Timeout
- If-Then-Else
- Enrich
To define the event selection criteria
- Select Configuration > Event Policies and click Create.
- In the Event Selection Criteria, define a condition to select events from the class EVENT.
The following image illustrates how the event selection criteria will look.
To build the policy workflow
On the Advanced Enrichment page, perform the following steps to build the policy workflow:
- Add the Timeout action. Under the Timeout Settings, define the duration and the unit.
- Add the If action. Under the If Settings, define a condition to check unassigned events with the status, Major.
- Under Then, add an Enrich action to change the event severity to Critical.
- Under the previous action, add an Enrich action to change the owner to Admin.
Results
The resulting policy workflow enriches the severity and changes the owner of all the unassigned Major events, after a duration of 6 hours has lapsed as shown in the following image: