With Custom Alerts you are able to configure email alerts using predefined templates so you're notified about specific activity in your environment. Which of the following outlines the steps required to properly create a custom alert rule?
A.
Choose the template you would like to configure, setup how often you would like the alert to run, and then schedule the alert
B.
Choose the template you would like to configure, preview the search results, and then schedule the alert
C.
Create the query for the alert, setup the email template for the alert, and then set the schedule for the alert
D.
Create a new custom template, configure the email template, and then create the custom query for the alert
These are the steps required to properly create a custom alert rule. Custom Alerts are a feature that allows you to configure email alerts using predefined templates so you’re notified about specific activity in your environment. You can choose from various templates that cover different use cases, such as suspicious PowerShell activity, network connections to risky countries, etc. You can also preview the search results of the template before scheduling the alert. You do not need to create the query for the alert, setup the email template for the alert, or create a new custom template, as these are already provided by the predefined templates.
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit