SNS / WebHook Integration ended reason, replaced_by_id, and replaced_by_status fields

SNS / WebHook Integration ended reason, replaced_by_id, and replaced_by_status fields

0
Created On 09/26/18 13:45 PM - Last Modified 07/19/22 23:08 PM


Resolution


Three new fields are unique to SNS and WebHook Integration notifications.  These fields are used to identify why the alert ended and what alert is now in its place.

 

ended_reason

Explains why the alert ended.  Possible values:

  • from_api
  • new_alert
  • from_scan
  • not_present_after_scan
  • signature_deleted
  • custom_signature_deleted
  • suppression_created
  • suppression_deactivated
  • custom_risk_level_created
  • custom_risk_level_deleted

 

replaced_by_id

ID of the new alert that replaced this alert

 

replaced_by_status

Status of the new alert that replaced this alert

 

Note: The above is written on 5/17/2017.  It is subject to change.



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000Clo9CAC&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail