Manage subscriptions
Receive an email notification when a rule triggers a detection. Subscriptions are configured and applied on a per-user basis using the email address tied to a user's account. If you are logging in for the first time or have never updated your subscriptions, you will see the Default Subscription created for every user.
You can manage subscriptions from the application settings or the detections settings menu.
To create a subscription:
- Go to Detections.
- In the toolbar, click the gear icon menu and click Manage Subscriptions. The Subscriptions page opens.
- Click the Create subscription button at the top right-side of the page. A blank subscription is displayed.
- Configure the subscription:
Subscription Name Enter a name for the subscription. Severities Select one of the following:
Severity Description Examples High Significant to fair impact with the potential to spread or escalate Malicious code execution, C2 communications, lateral movement, data exfiltration Moderate Fair impact with minimal potential to spread or escalate Activity that could indicate malicious intent, untargeted attacks with unknown success, data leakage, subversion of security or monitoring tools Low Little to no impact expected Potentially unauthorized software, devices, or resource use, untargeted adware or spyware, compromise of a personal device or device on an untrusted network, insecure configurations Confidences Select one of the following:
Confidence Minimum True-Positive Rate High 90% Moderate 75% Low 50% Categories Select a category from the list. For information, see Detections > Rule Categories.
Account Select the account the rule belongs to. Email Type Notification: Sends an email for each individual rule that becomes active.
Digest: Sends you a single email each day at the specified time (default 08:00 Eastern) summarizing rules that became active and/or were resolved during the previous day.
- Click Save.
To delete a subscription:
- Go to Detections.
- In the toolbar, click the gear icon menu and click Manage Subscriptions. The Subscriptions page opens.
-
Click the Actions menu at the left side of the rule and select Edit Subscription.
- Click Delete.
To disable a subscription:
- Go to Detections.
- In the toolbar, click the gear icon menu and click Manage Subscriptions. The Subscriptions page opens.
- Click Delete.