Rule ID

The ID that matches the rule that triggered the alert

Core Alert Fields shortText

Details

IDincident_ruleid
CLI Nameruleid
TypeshortText
Version-1
RequiredNo
Read OnlyNo
Use as KPINo
SearchableNo
{
    "associatedToAll": true,
    "caseInsensitive": true,
    "cliName": "ruleid",
    "closeForm": false,
    "content": true,
    "description": "The ID that matches the rule that triggered the alert",
    "editForm": true,
    "group": 0,
    "hidden": false,
    "id": "incident_ruleid",
    "isReadOnly": false,
    "locked": false,
    "name": "Rule ID",
    "neverSetAsRequired": false,
    "openEnded": false,
    "ownerOnly": false,
    "propagationLabels": [
        "all"
    ],
    "required": false,
    "sla": 0,
    "system": false,
    "threshold": 72,
    "type": "shortText",
    "unmapped": false,
    "unsearchable": true,
    "useAsKpi": false,
    "version": -1,
    "fromVersion": "6.5.0",
    "x2_fields": "matching_service_rule_id",
    "Aliases": [
        {
            "cliName": "chronicleruleid",
            "type": "shortText",
            "name": "Chronicle Rule ID"
        }
    ]
}