This section allows you to add fields and values to the alert triggered by the rule. The following table describes the parameters you can use in the output section of a rule.
Name | Type | Required | Default | Description |
|---|---|---|---|---|
| String | Yes | Not applicable | The name of the field to add to the alert. |
| String | Yes | Not applicable | A match expression, for example it could be a field name, or part of a field name or from multiple fields. |
The following rule adds the fields username and action, along with the values shown, to the alert triggered by the rule.
id: 123
version: 123456789
name: Test output rule
output:
- field: username
value: domain + "/" + tolower(username)
- field: action
value: "denied"