Forum Discussion

Thijs Lecomte's avatar
Thijs Lecomte
Bronze Contributor
Apr 09, 2020

Custom Entities

Hi all   When you create a rule and configure your Entities, there used to be a line that says  "More custom entities coming soon", this seems to have been removed.   Can the PG share any announ...
  • Ely_Abramovitch's avatar
    Apr 16, 2020

    Hi,Thijs Lecomte 

     

    This is Ely from the product group.

    Supporting more entities as part of scheduled alerts is indeed required and planned. We are working on a solution to support a more flexible way to map entities that will support more entity types and more fields for each entity.

     

    The requirement for supporting arrays is a bit different and will require some thought.

    A short-term solution can be to use the mv-expand operator to create a line for each IP address and then map them using the regular way. You can then use the Alert Grouping feature (now available in public preview) to make sure you group the alerts as to not generate too many incidents.

Resources