BookmarkSubscribeRSS Feed
☑ This topic is solved. Need further help from the community? Please sign in and ask a new question.
Idanar
Obsidian | Level 7

Hi everyone,

 

How can I create an automatic action to move an Alert from one queue to another, based on specific characteristics? 

 

For example, I have a queue for suppressed scenario activities, and alerts are moving to this queue after suppression with an alert score of 0.

After some time, the score of the suppressed alert is changing and gets an actual score (let's say 100). I want that after the alert activity got out from suppression, it will return to the relevant queue.

 

How can I define an automatic rule like that? 

I thought about a workflow, but it allows me to create a workflow on case(s) object, while I would like it to work on an Alert/Queue.

 

Thanks for the help.

1 ACCEPTED SOLUTION

Accepted Solutions
_austin_
SAS Employee

Hello @Idanar ,

Apologies, I get it now. In your case no new alerting events are involved. When the alert reactivates you would like the alert to re-enter the queue it was in at the time it became suppressed. While the current behavior is how the system was designed - it is not a defect per se - I see how your suggestion would be an improvement for analysts and administrators. I will submit a feature request to product management based on this discussion. 

Best regards,

Austin

View solution in original post

3 REPLIES 3
_austin_
SAS Employee

Hello,

You may be able to use normal alert routing. 

Does the new activity recommend a destination queue? If so, what are the routing priorities for the two queues? Is the routing priority for the suppression queue higher or lower than the routing priority for the destination queue?

If your alerting event or scenario fired event recommends a queue and that queue has a higher routing priority than the suppression queue, the alert will get routed to the higher priority queue automatically.

Idanar
Obsidian | Level 7

Hi @_austin_ ,

Thanks for the response.

Let's say there is an activity that has been routed to the correct queue, and after an investigator review this alert, he decides to suppress the activity for 1 month. when he does that, the alert score is decreasing to 0 and is routed to the suppression queue. (Until here, it's working fine)

After a month, the alert is getting back to its initial score, which is ok, but we need it to return to the initial queue.

 

my configuration is:

1. In the domain, there is an option for Suppressed event queue configured to a new queue called "HR_Close_S_q".

2. When the scenario fired-events are generated they are routed to a queue: "HR_Close_q" with a priority of 26.

3. when a user suppressed a fire event, the alert score is updated to 0 and the alert itself is routed to the "HR_Close_S_q" queue (which has a priority of 29)

4. after sometime configuration, the fire event is restored, and the score of the event returns to the initial score, but the alert is not routed back to the relevant queue ("HR_Close_q")

 

Idanar_0-1685866100015.png

 

_austin_
SAS Employee

Hello @Idanar ,

Apologies, I get it now. In your case no new alerting events are involved. When the alert reactivates you would like the alert to re-enter the queue it was in at the time it became suppressed. While the current behavior is how the system was designed - it is not a defect per se - I see how your suggestion would be an improvement for analysts and administrators. I will submit a feature request to product management based on this discussion. 

Best regards,

Austin

Discussion stats
  • 3 replies
  • 781 views
  • 0 likes
  • 2 in conversation