Alerts Metadata

The table below describes the metadata that is captured in each alert:

Slack

Email

Webhook

  • Findings

  • Where

    • Ticket - Title and number

    • Fields - Field name

    • Project - Project name

    • Project type

  • When

    • Timestamp

  • Detection rules

  • Policies violated

  • Who

    • User name

  • Link to the violations dashboard in console

  • Event - Created, Edited

  • Finding snippets

Remediation actions

  • Findings

  • Where

    • Ticket - Title and number

    • Fields - Field name

    • Project - Project name

    • Project type

  • When

    • Timestamp

  • Detection rules

  • Policies violated

  • Who

    • User name

  • Event - Created, Edited

  • Finding snippets

No remediation actions

  • Detection rule link

  • Detection rule violated

  • Permalink

  • violation link

  • Violation time

  • Integration metadata

  • Findings

See https://help.nightfall.ai/operationalizing-dlp/integrating-with-security-tools/integrating-with-siem#webhook-payload-examples

Last updated