Classify events using a classification key in an integration ingestion.
When an integration fetches indicators, it populates the rawJSON object in the indicator object. When classifying data, you want to select an attribute that can determine the indicator.
You can use this procedure for creating a classifier or duplicating an existing classifier.
Under Get data, select from where you want to pull the information based on which you will classify the incident types.
Pull from instance: Select an existing integration instance.
Select schema: When supported by the integration, this will pull all the fields for the integration from the database from which you can select by which to classify the events.
Upload JSON: Upload a formatted JSON file which includes the field by which you want to classify.
Select
→ → → → → → .If you want to duplicate the classifier, select the relevant classifier and then duplicate it.
In the Get data field, select how to retrieve the data to classify the events.
In the Select Instance field, select the instance or JSON file from where you want to choose the value.
Save the classifier.
Go to
→ .Select the integration to which you want to apply the classifier.
In the integration settings, under Classifier, select the classifier you created and click Save.