Replies: 1 comment 1 reply
-
for that purpose, you have to use the |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Problem
There is currently not a way to indicate that an activity was blocked due to reasons like Corporate Policy, Allow/Blocklisting, etc. The closest alternative would be to enable the
Malware
profile and use thedisposition
field but as noted above, just because something is blocked doesn't mean it's malicious.Proposal
Add an additional item to
status_id
calledBlocked
that can be used to indicate the "thing" described by the event was seen and prevented. Additional details as to why it was blocked can be included in the existingstatus_detail
field.4 votes ·
Beta Was this translation helpful? Give feedback.
All reactions