pub struct SiemAlert {
    pub title: String,
    pub description: String,
    pub severity: AlertSeverity,
    pub date: i64,
    pub tags: Vec<String>,
    pub techniques: Vec<MitreTechniques>,
    pub rule: String,
    pub log: SiemLog,
    pub aggr_limit: i64,
    pub aggr_key: String,
}
Expand description

Basic Alert format

Fields

title: Stringdescription: Stringseverity: AlertSeverity

Severity of the alert

date: i64

When the alert was generated

tags: Vec<String>

List of tags to be added to the alert

techniques: Vec<MitreTechniques>

List of MitreAtack Techniques

rule: String

Name of the rule that generated the alert

log: SiemLog

The log that triggered this alert

aggr_limit: i64

Time at witch the Alert system must create a new case

aggr_key: String

Key to be used in the aggregation of alerts as to join multiple alerts into one

Trait Implementations

Returns a copy of the value. Read more
Performs copy-assignment from source. Read more
Formats the value using the given formatter. Read more
Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations

Blanket Implementations

Gets the TypeId of self. Read more
Immutably borrows from an owned value. Read more
Mutably borrows from an owned value. Read more

Returns the argument unchanged.

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

The resulting type after obtaining ownership.
Creates owned data from borrowed data, usually by cloning. Read more
Uses borrowed data to replace owned data, usually by cloning. Read more
The type returned in the event of a conversion error.
Performs the conversion.
The type returned in the event of a conversion error.
Performs the conversion.