Role Availability | Read-Only | Investigator | Analyst | Manager |
Note: By default, this rule is disabled.
Note: These rules use the event_severity field with the values low, medium, high, and critical, and the event_action field with the values created, deleted, and updated.
- Go to Settings > Rules.
-
Locate the USM Anywhere Investigations Notification rule and click the
icon. This turns the
icon green. To disable the rule, toggle the icon to its original status.
- Click an investigation to display its details.
- Go to Settings > Rules.
-
Locate the USM Anywhere Investigations Notification rule and click the
icon.
- Make the changes as needed and click Save Rule. See Notification Rules from the Orchestration Rules Page for more information on editing notification rules.
Note: The destination email field includes the emails of the users created in the environment as the role of Managers. See Role-Based Access Control (RBAC) in USM Anywhere for more information.