Incident_identifier*
During alert correlation, BigPanda assigns correlated events an incident identifier. This identifier is used throughout the BigPanda system to recognize if two events are related to each other and is critical to ensure that BigPanda events can be resolved. Incident identifiers are created based on the tags and event data sent to BigPanda for each event.
By default, the incident identifier is a combination of the correlating events’ primary and secondary properties.
The incident_identifier may also be called the incident_key. The value for the incident_key can be overridden by explicitly setting a property in an alert payload, such as “incident_identifier”: “${field1}${field2}”.
Reserved word
This term is reserved for system use and cannot be changed or redefined for custom enrichment.
Lowercase only
When sending this field to BigPanda ensure that it is lowercase only.