Skip to content

docs: add Alert Events Threshold Trigger documentation#2762

Open
Imothep-Akonis wants to merge 1 commit intoSEKOIA-IO:mainfrom
Akonis-cybersecurity:docs/alert-events-threshold-trigger
Open

docs: add Alert Events Threshold Trigger documentation#2762
Imothep-Akonis wants to merge 1 commit intoSEKOIA-IO:mainfrom
Akonis-cybersecurity:docs/alert-events-threshold-trigger

Conversation

@Imothep-Akonis
Copy link

Add comprehensive documentation for the new AlertEventsThresholdTrigger feature including:

  • Feature overview and use cases
  • Configuration parameters with detailed descriptions
  • Volume-based and time-based threshold logic explanation
  • Trigger output structure and trigger_context object
  • State management and persistence details
  • Prometheus observability metrics
  • Example configurations for common use cases
  • Manifest example
  • Implementation notes and optimization details
  • Comparison with related triggers

This trigger enables intelligent batching of alert playbook executions based on event accumulation thresholds, reducing noise and cost for high-volume alerts.

Ref: SEKOIA-IO/automation-library#1721

Add comprehensive documentation for the new AlertEventsThresholdTrigger
feature including:

- Feature overview and use cases
- Configuration parameters with detailed descriptions
- Volume-based and time-based threshold logic explanation
- Trigger output structure and trigger_context object
- State management and persistence details
- Prometheus observability metrics
- Example configurations for common use cases
- Manifest example
- Implementation notes and optimization details
- Comparison with related triggers

This trigger enables intelligent batching of alert playbook executions
based on event accumulation thresholds, reducing noise and cost for
high-volume alerts.

Ref: SEKOIA-IO/automation-library#1721

Co-Authored-By: Claude Opus 4.5 <[email protected]>
@github-actions
Copy link

Newest code from Imothep-Akonis has been published to preview environment

🚀 Latest deployment was built on 2026-01-26 12:50:04 (b9c20f84e717e1837db2104d9a05fae099030308).

@github-actions
Copy link

This PR was marked as stale because it has been open for 30 days with no activity.

@github-actions github-actions bot added the stale label Feb 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant