Adding a policy
Add a policy rule to associate the query with the channel.
To add a policy rule:
-
Go to Alerts > Policy Rules.
-
Click ADD RULE.
-
In the Rule Name field, enter a name for the rule.
-
In the Rule Notes field, enter a description for the rule.
-
If you selected All Organizations in the Organization dropdown list at the top of the GUI, you can select which organization that the rule will belong to.
-
If you want the rule to be active, select the Enable Rule checkbox.
-
In the Event Type dropdown list, select Asset, Service, Software, Vulnerability, Detector, or Scan.
-
In the Event Name dropdown list, select the event.
-
In the Level dropdown list, select Notice, Warning, or Critical.
-
In the Channel Name dropdown list, select the channel.
-
In the Channel Notes field, enter a description of the channel.
-
In the Query Name dropdown list, select the query.
-
In the Query Notes field, enter a description of the query.
-
If the Criteria dropdown list is displayed, select equal, greater, less, greater_equal, or less_equal.
-
If the Threshold Count field is displayed, enter the number of times the criterion is matched before the alert is triggered.
-
Click Save.