Setting Special Severity Levels

You can customize or conditionalize the event-severity levels reported by SmartConnectors. Customizing means pre-setting a given SmartConnector's filter to one specific severity level; conditionalizing is essentially the same, but with the addition of a filter condition to determine when the pre-set severity level is reported.

To configure a custom or conditional severity level:

  1. Choose the Connectors resource tree in the Navigator panel.

  2. In the Connectors resource tree, right-click the appropriate SmartConnector and choose Configure.

  3. In the Connector Configuration Editor, select the Connector: Default: Filters tab.

  4. In the Filters tab, select a severity level.

  5. In the Filter Condition dialog box choose a field, a logical operator, and enter a value for the condition.

  6. Click OK in the Filter Condition dialog box and Apply or OK in the Connector Configuration Editor.

In the example, we selected the "Very-High Severity” filter and defined a condition in which Category Significance contains Hostile. When this condition is met, the severity of the event becomes "Very-High."

For more information, see Managing SmartConnector Filter Conditions.