Detect and Respond Context Creation Models
List of Requested Context Creation Models
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
Context Creation Model Create or Update Config
If true, portal and API will not display new events
falseIf true, alerts will not be processed by policies and integrations
falseCategories for the context model
["system"]Context model description
context model descriptionDiscard lists are NQL statements that if matched do not get processed through the event. It enables skipping certain combinations without disabling the context model
["bits > 10000"]If true, the context model is enabled
trueNumber of seconds the context creation model will remain active
3600Factors for the context model
["srcip"]Name of the context model
new_ndm_nameThe lookback period for the context model. Min 15 seconds. Max 1 hour (3600)
300When ongoing updates should be sent. Max 6 hours (21600). 0 for disabled
0The context of record to be used for the context model
flowPossible values: Requested Context Creation Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the context creation model to be returned.
Requested Context Creation Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the context creation model to be updated
Context Creation Model Create or Update Config
If true, portal and API will not display new events
falseIf true, alerts will not be processed by policies and integrations
falseCategories for the context model
["system"]Context model description
context model descriptionDiscard lists are NQL statements that if matched do not get processed through the event. It enables skipping certain combinations without disabling the context model
["bits > 10000"]If true, the context model is enabled
trueNumber of seconds the context creation model will remain active
3600Factors for the context model
["srcip"]Name of the context model
new_ndm_nameThe lookback period for the context model. Min 15 seconds. Max 1 hour (3600)
300When ongoing updates should be sent. Max 6 hours (21600). 0 for disabled
0The context of record to be used for the context model
flowPossible values: Requested Context Creation Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the context creation model to be deleted
An empty array
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
No content
The ID of the context creation model to be enabled
Requested Context Creation Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the context creation model to be disabled
Requested Context Creation Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
The ID of the context creation model to be reseted
Requested Context Creation Model
Bad Request. Typically due to a malformatted JSON body, or parameter values are not validating.
Access token is missing or invalid
Access is forbidden
Unknown Error Occurred
Last updated