If resulting table has a column severity, then it will be used as the alert's severity. I could not find anything about this in the documentation.
Moreover, it expects everything in lower case. A severity "Medium" results in
signature="Unexpected error: 'Medium'."
Error message could be improved, stating which field caused this issue. I had a MV field with firewall severities which resulted in a much stranger error message (something with list type not supported).
Hello @kwizzz,
A refinement of the code about this and also on the PAP/TLP fields too was done.
Documentation will be reviewed too.
A fix will be provided soon
Thank you
Request Type
Bug
Work Environment
v3.1 Queen
Problem Description
If resulting table has a column
severity
, then it will be used as the alert's severity. I could not find anything about this in the documentation.Moreover, it expects everything in lower case. A severity "Medium" results in
signature="Unexpected error: 'Medium'."
Error message could be improved, stating which field caused this issue. I had a MV field with firewall severities which resulted in a much stranger error message (something with list type not supported).
Steps to Reproduce
| eval severity=risk