Notifications¶
Notifications send messages. You can add a notification
section anywhere that you want the output of a trigger
to be a message, such as in an alert or detection. In a detection, the notification
section can send a message when the specified activity (such as a potential threat) is detected.
TeskaLabs LogMan.io uses TeskaLabs ASAB Iris, a TeskaLabs microservice, to send messages.
Warning
To avoid notification spam, only use notifications for highly urgent and well-tested detection rules. Some detections are better suited to be sent as events through Elasticsearch and viewed in the LogMan.io web app.
Notification types¶
Currently, you can send messages via email.