Create custom alerts #892
-
Are we able to create custom alerts using FalconPy? From the wiki page, it seems like we can only...
I'm not quite sure whether this is the newest documentation... But if we are not able to do that for now, is there any plan for this in the coming future? Thank you very much for your help! |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 4 replies
-
Hi @TaihouKai Thank you for the question! The Alerts library itself does not provide the ability to generate custom alerting. As designed it returns alerts generated from different Falcon modules. Alerts provide insight into potential security issues by delivering combined notifications regarding detected activity within your tenant. (Similar to event streams.)
Currently these Falcon Modules generate alerts
That said, I did want to ask a clarifying question on your use case. What sort of event are you looking to generate an alert for? We can for example create things like scheduled searches or indicator based rules that alert when specific activity is observed. This can also extend to things like IOAs or Firewall rules. Let me know a bit more about what sort of activity you are looking to be alerted on and we can walk through some other options. |
Beta Was this translation helpful? Give feedback.
Hi @TaihouKai
Thank you for the question!
The Alerts library itself does not provide the ability to generate custom alerting. As designed it returns alerts generated from different Falcon modules.
Alerts provide insight into potential security issues by delivering combined notifications regarding detected activity within your tenant. (Similar to event streams.)
Currently these Falcon Modules generate alerts
That said, I did want to ask a clarifying question on your use case. What sort of event are you looking to generate an alert for? We can for exa…