Skip to content

[DOC] Security Analytics - Need documentation about mustache template variables in detector trigger message #4817

Open
@eirsep

Description

@eirsep

What do you want to do?

  • Request a change to existing documentation
  • Add new documentation
  • Report a technical problem with the documentation
  • Other

Tell us about your request. Provide a summary of the request and all versions that are affected.
Security Analytics plugins creates detectors to run security rules on data.
When rule is matched against documents findings and alerts are created.
We allow users to configure alerts and notifications when such findings are created.
The notification contains an option to add a message body with mustache templates to provide contextual variables for detector and underlying alerting monitor
{{ctx.detector}} variable value looks like : {_id=qVGldIkB0UfzAtaegDPc, _version=1, name=test-detector, enabled=true}

What other resources are available? Provide links to related issues, POCs, steps for testing, etc.

Similar to Alerting notification message mustache template variables
https://opensearch.org/docs/latest/observing-your-data/alerting/monitors/#available-variables

Metadata

Metadata

Labels

1 - BacklogIssue: The issue is unassigned or assigned but not startedSev3Medium priority. Content that's missing, driven by dev, PM or the community.security-analytics

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions