We are working on implementing API call integration to extract alerts and then process them into with tfsnow (Service Now).
The below article, for the alerts category, do you have more information available on each category?
category |
string Alert categories. The following values are allowed:
azure, adSync, applicationControl, appReputation, blockListed, connectivity, cwg, denc, downloadReputation, endpointFirewall, fenc, forensicSnapshot, general, iaas, iaasAzure, isolation, malware, mtr, mobiles, policy, protection, pua, runtimeDetections, security, smc, systemHealth, uav, uncategorized, updating, utm, virt, wireless, xgEmail