Thijs Lecomte
Apr 09, 2020Bronze Contributor
Custom Entities
Hi all When you create a rule and configure your Entities, there used to be a line that says "More custom entities coming soon", this seems to have been removed. Can the PG share any announ...
- Apr 16, 2020
This is Ely from the product group.
Supporting more entities as part of scheduled alerts is indeed required and planned. We are working on a solution to support a more flexible way to map entities that will support more entity types and more fields for each entity.
The requirement for supporting arrays is a bit different and will require some thought.
A short-term solution can be to use the mv-expand operator to create a line for each IP address and then map them using the regular way. You can then use the Alert Grouping feature (now available in public preview) to make sure you group the alerts as to not generate too many incidents.