End-of-Life (EoL)

Classify Events Using a Classification Key

Follow these instructions to classify events using a classification key in an integration ingestion.
When an integration fetches incidents, it populates the rawJSON object in the incident object. The rawJSON object contains all of the attributes for the event. For example, source, when the event was created, the priority that was designated by the integration, and more. When classifying the event, you want to select an attribute that can determine what the event type is.
  1. Go to
    Classification & Mapping
  2. Click
    and select
    Incident Classifier
  3. Under
    Get data
    , select from where you want to pull the information based on which you will classify the incident types.
    • Pull from instance - select an existing integration instance.
    • Select schema - when supported by the integration, this will pull all of the fields for the integration from the database from which you can select by which to classify the events.
    • Upload JSON - upload a formatted JSON file which includes the field by which you want to classify.
  4. Under
    Select Instance
    , select the instance from where you want to choose the value.
  5. Under
    Fetched data
    select the value by which you want to classify the events.
  6. Drag values from the
    Unmapped Values
    column to the relevant incident type on the right.
    You can optionally choose a default incident type for unclassified incidents from
    Direct unclassified events to: Select
  7. Click
  8. Navigate to the
    Servers & Services
    1. Select the integration to which you want to apply the classifier.
    2. In the integration settings, under
      , select the classifier you created and click

Recommended For You