The description of this Sentinel Scheduled Alert Rule Template.
The query of this Sentinel Scheduled Alert Rule Template.
The ISO 8601 timespan duration between two consecutive queries.
The ISO 8601 timespan duration, which determine the time period of the data covered by the query.
The alert severity of this Sentinel Scheduled Alert Rule Template.
A list of categories of attacks by which to classify the rule.
The alert trigger operator, combined with trigger_threshold, setting alert threshold of this Sentinel Scheduled Alert Rule Template.
trigger_threshold
The baseline number of query results generated, combined with trigger_operator, setting alert threshold of this Sentinel Scheduled Alert Rule Template.
trigger_operator