Customizing the Offense Email Template


Use the QRadar® on Cloud Self Serve app to customize the content that is included in the email notifications when an offense is triggered. 


Procedure

  1. Open the Admin settings, and click QRadar on Cloud Self Serve.
  2. Click Custom Offense Email Template.
  3. Copy the current template, update as required and then paste the updated version. Edit the parameters in the <body> or <subject> elements to include the information that you want to see.

     

    The following lists provide the values that you can use in the offense template. $Label values provide the label for the item and the $Value values provide the data.

    Offense parameters
    $Value.DefaultSubject
    $Value.Intro
    $Value.OffenseId
    $Value.OffenseStartTime
    $Value.OffenseUrl
    $Value.OffenseMRSC
    $Value.OffenseDescription
    $Value.EventCounts
     
    $Label.OffenseSourceSummary
    $Value.OffenseSourceSummary
     
    $Label.TopSourceIPs
    $Value.TopSourceIPs
     
    $Label.TopDestinationIPs
    $Value.TopDestinationIPs
     
    $Label.TopLogSources
    $Value.TopLogSources
     
    $Label.TopUsers
    $Value.TopUsers
     
    $Label.TopCategories
    $Value.TopCategories
     
    $Label.TopAnnotations
    $Value.TopAnnotations
     
    $Label.ContributingCreRules
    $Value.ContributingCreRules
  4. Submit your changes and click Save.
  5. On the Admin tab, click Advanced > Deploy Full Configuration.
  6. Submit your changes and click Save.
  7. On the Admin tab, click Advanced > Deploy Full Configuration.

Results

When you deploy the full configuration, QRadar services restart. During this time, events and flows are not collected, and offenses are not generated. After the full configuration deploy the changes will take effect and the new custom offense email template will be the one in place.