Manually update event rules to reflect current event information because once an
event rule is created, the Event Additional info and
Event
Raw info fields are not automatically updated.
Before you begin
Role required: evt_mgmt_admin
About this task
To automatically filter out irrelevant alerts or transform and standardize alert data for better response, you can also use Ignore automation and Enrich automation.
Procedure
-
Navigate to .
-
Select the event.
-
Select Refresh Event Rule.
-
Select the event rules to refresh.
-
Select Refresh Selected.
If you selected multiple event rules, then the last selected item in the list opens in the Event Rule Designer.
Note: If the current event rule regex expressions do not match the selected event after the refresh, the update fails and an error message appears specifying the problematic fields. This safeguard ensures that your previously
defined event rule regex expressions are not broken due to the refresh.