Use the QRadar® on Cloud Self
Serve app to customize the content that is included in the email notifications when an offense is
triggered.
Procedure
- Open the Admin settings, and click QRadar on Cloud Self
Serve.
- Click Custom Offense Email Template.
- Copy the current template, update as required and then paste the updated version. Edit
the parameters in the
<body> or <subject> elements to
include the information that you want to see.
The following lists provide the values that you can use in the offense template. $Label values
provide the label for the item and the $Value values provide the data.
- Offense parameters
- $Value.DefaultSubject
- $Value.Intro
- $Value.OffenseId
- $Value.OffenseStartTime
- $Value.OffenseUrl
- $Value.OffenseMRSC
- $Value.OffenseDescription
- $Value.EventCounts
-
- $Label.OffenseSourceSummary
- $Value.OffenseSourceSummary
-
- $Label.TopSourceIPs
- $Value.TopSourceIPs
-
- $Label.TopDestinationIPs
- $Value.TopDestinationIPs
-
- $Label.TopLogSources
- $Value.TopLogSources
-
- $Label.TopUsers
- $Value.TopUsers
-
- $Label.TopCategories
- $Value.TopCategories
-
- $Label.TopAnnotations
- $Value.TopAnnotations
-
- $Label.ContributingCreRules
- $Value.ContributingCreRules
- Submit your changes and click Save.
- On the Admin tab, click Advanced >
Deploy Full Configuration.
- Submit your changes and click Save.
- On the Admin tab, click
.
Results
When you deploy the full configuration, QRadar services restart. During
this time, events and flows are not collected, and offenses are not generated. After the full
configuration deploy the changes will take effect and the new custom offense email template will be
the one in place.