Create a CIM non-compliance alert
The Ingest Monitoring alert system provides the Common Information Model (CIM) non-compliance detection feature, which enables the following results:
-
Field extraction coverage, which triggers an alert when the ratio of non-extracted suggested fields is below the threshold.
-
CIM value validation coverage, which triggers an alert when the ratio of non-expected values appearing in events is below the threshold.
Follow the guided setup to can customize the alert rule by setting up alert frequency, expiry, throttle, and severity.
Provide alert details
Configure the alert details to define the name, description, and data source for your CIM non-compliance alert.
-
On the Alerts page, select Create alert.
-
Select the CIM non-compliance template.
-
Enter a name for the alert, such as Authentication CIM Compliance - firewall.
-
(Optional) Add a description.
-
Choose the CIM data model and dataset to monitor, such as Authentication.Authentication or Network_Traffic.All_Traffic.
-
After choosing a data model, the source type drop-down menu populates with values that are mapped to that model. Select the source type you want to monitor.Note: Only accelerated data models are supported. If the data model you select isn't accelerated, the sourcetype dropdown in the next step will display no options.
-
After choosing a data model, a table populates all required and suggested CIM fields for the selected dataset.
-
By default, all fields are selected. Deselect any fields you do not want to monitor.
-
Select Next.
Set alert trigger rules
-
Set the field coverage threshold, which triggers the alert when the percentage of events containing a monitored field drops below the set value. By default, this threshold is set to 80%.
-
Set the CIM value compliance threshold, which triggers the alert when the percentage of field values matching the expected CIM values drops below the set value. By default, this threshold is set to 80%.
- Configure the alert schedule and throttle:
-
In the Alert schedule section, define how often the alert runs. Select one of the available options:
-
every 4 hours
-
daily
-
weekly
-
- (Optional) Deselect Exclude weekends (Saturdays and Sundays) to skip weekend evaluations.
-
In the Expires after section, determine how long the triggered alert remains active. The default is 24 hours.
-
Select Throttle to suppress duplicate alerts within a time window. The default is 60 minutes for CIM alerts.
-
- Select Next.
Set alert actions
-
Set the severity level for the alert. Select one of the available options:
-
Info
-
Low
-
Medium
-
High
-
Critical
-
-
Select Next.
Review and activate your alert
Perform the following steps to review and activate your alert:
-
Review all configured settings: data model and dataset, source type, field coverage and CIM value validation thresholds, schedule, expiry, throttle settings, and severity.
-
Select Create to save the alert.
The alert is now scheduled and runs according to your configured schedule. When the alert condition is met, such as when field coverage or CIM value validation falls below the threshold, it appears in the Triggered alerts tab.