Hello,
So I created this rule that triggers on Azure risky signins:
Ans as you can see I made an override for the azure.signinlogs.properties.risk_level_during_signin
field.
But now the alert I configured triggers on low, medium and high risky signins. While actually I only want alerts for high risky signins. Could a functionality be added that the alert only triggers when a certain condition is met, for example when "rule severity has one or more values"?
Grtz
Willem