Skip to main content
Version: 3.2.0

Templates

Each event uses information from a template when it is created. The Template Manager manages and creates new templates to use as preset values for alerts on saved searches.

info

See Role Overview for capabilities required to manage templates.

Managing Templates

The following image shows the Template Manager UI:

The search field can be used to filter by template name.

Use the following buttons to manage templates:

ButtonFunction
Add Template
Copy Template
Save Template
Delete Template

Create a template

To create a template:

  1. Click the Add Entry button at the bottom of the list.
  2. Give the template a unique name.
  3. Set the correct values for the template referring to Event Creation > Alert Action Setup.
  4. Click the save button on the upper right side of the template section.

The following options are available:

InformationDescription
Template nameThe name of the template.
TenantThe tenant specifies what index and collection the events created by this alert are stored in.
AssigneeThe default assignee for the AME event.
ImpactThe impact of the alert. Typically, an estimation.
UrgencyThe urgency of the alert. Typically, an estimation.
NotificationThe notification scheme to use for the event
TagsA list of tags to assign to the event
Notable fieldsA list of fields is to be shown under the Notable Fields tab. Alternatively, a wildcard can be set to show all fields. Note: Internal AME Fields and the _raw field always have to be explicitly listed.
StatusThe default status for events created by the alert.
ResolutionThe default resolution.
Time-to-live (TTL)How long an event should be kept alive.
TTL TargetIf TTL is set, the target status for the event after the TTL is reached.
Append alertIf set, Alerts matching defines keys will be appended to existing open events.
Append strictIf set, Alerts with ...
Notification on appendIf set, appended Alerts will also trigger notifications.
Append keysA set of keys that are used as a criteria to group events
Append modeThe mode to use when an alert is appended to existing events
info

The default template can not be deleted.

info

See Event Aggregation for more details about appending alerts.

danger

Displaying _raw for notable fields will cause the KV Collection faster and may cause issues over time.

Update and delete a template

Revise the information and press the Save Template button to update a template. To delete a template, press the Delete Template button next to the save button in the upper right corner of the template section.

danger

Deleting a template will not update your saved searches relying on that template. Please make sure to update your saved searches beforehand.