Creates a new guidance entry. Guidance provides a business context that informs Auto Triage reasoning during alert triage. For more information, refer to our Guidance documentation.
The guidance name. Maximum 200 characters. This property is required.
An optional description of the guidance. Maximum 2,000 characters.
The guidance text provided to Auto Triage during alert triage. Maximum 2,000 characters. This property is required.
Indicates whether the guidance is active. Defaults to true.
Defines which alerts this applies to.
The scope of alerts this applies to. Accepted values: "always", "by_source", "by_categories".
The security categories to match. Required when type is "by_categories".
The alert source type IDs to match. Required when type is "by_source".
A successful response.
Guidance provides business context that informs Auto Triage reasoning during alert triage. Each entry defines instructions or policies scoped to specific alerts, helping Auto Triage produce more accurate triage verdicts.
The unique identifier of the guidance entry.
The guidance name. Maximum 200 characters.
An optional description of the guidance.
The instruction text provided to Auto Triage during alert triage.
Whether the guidance is currently active.
Defines which alerts this applies to.
The scope of alerts this applies to. Accepted values: "always", "by_source", "by_categories".
The security categories to match. Required when type is "by_categories".
The alert source type IDs to match. Required when type is "by_source".
The timestamp when the guidance was created.
The timestamp when the guidance was last updated.
Invalid bearer token. If you receive this message more than once try creating a new Client ID/Client Secret or generating a new bearer token.
You don't have permission to access this resource.