IncidentRuleConditionTokenKey

Strings that can be used as SearchToken keys for incident rules

Values

classification

createdAt

has

id

likelyTargetEntity

not

phishReportCount

receiver

remediationEmailCount

reportCountFromInbox

sender

severity

subject

threatCount

threatIndicator

type

user

vipReportCount