You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/thehive/api/alert/merge.md
+57-57Lines changed: 57 additions & 57 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,62 +25,62 @@ With:
25
25
!!! Example ""
26
26
27
27
```json
28
-
{
29
-
"_id": "~6658533455",
30
-
"id": "~6658533455",
31
-
"createdBy": "florian@strangebee.com",
32
-
"updatedBy": "florian@strangebee.com",
33
-
"createdAt": 1620397519028,
34
-
"updatedAt": 1624373852175,
35
-
"_type": "case",
36
-
"caseId": 114,
37
-
"title": "User connected to known malicious IP over Telnet / Malicious payload detected",
38
-
"description": "EDR automated alert: the user robb@training.org has connected to known malicious IP over Telnet\n\nEDR automated alert: malicious payload detected on computer PC-Robb\n \n#### Merged with alert #90e044 User posted information on known phishing URL\n\nSIEM automated alert: the user robb@training.org has posted information on a known phishing url",
39
-
"severity": 2,
40
-
"startDate": 1620396059728,
41
-
"endDate": null,
42
-
"impactStatus": null,
43
-
"resolutionStatus": null,
44
-
"tags": [
45
-
"log-source:proxy",
46
-
"source:edr",
47
-
"log-source:endpoint-protection",
48
-
"source:siem",
49
-
"protocol: telnet",
50
-
"ex2"
51
-
],
52
-
"flag": false,
53
-
"tlp": 3,
54
-
"pap": 2,
55
-
"status": "Open",
56
-
"summary": null,
57
-
"owner": "florian@strangebee.com",
58
-
"customFields": {
59
-
"businessUnit": {
60
-
"string": "Finance",
61
-
"order": 0
62
-
},
63
-
"location": {
64
-
"string": "Sydney",
65
-
"order": 1
28
+
{
29
+
"_id": "~6658533455",
30
+
"id": "~6658533455",
31
+
"createdBy": "florian@strangebee.com",
32
+
"updatedBy": "florian@strangebee.com",
33
+
"createdAt": 1620397519028,
34
+
"updatedAt": 1624373852175,
35
+
"_type": "case",
36
+
"caseId": 114,
37
+
"title": "User connected to known malicious IP over Telnet / Malicious payload detected",
38
+
"description": "EDR automated alert: the user robb@training.org has connected to known malicious IP over Telnet\n\nEDR automated alert: malicious payload detected on computer PC-Robb\n \n#### Merged with alert #90e044 User posted information on known phishing URL\n\nSIEM automated alert: the user robb@training.org has posted information on a known phishing url",
0 commit comments