IBM QRadar SOAR

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Notifications and line breaks

    Posted Wed May 06, 2020 09:55 AM

    Hey Guys,

    I'm hoping that one of you can help me out real quick. The default notifications look like they should have line breaks and character returns in them but when we receive the email they are all just smushed into one line.

    What is the recommended way to get character returns and new lines into the notifications that are sent from Resilient?

    Example of one of our notifications:

    Incident Membership Change
    You have been added as a member tosfdd923. Incident ID: 7777 Incident Name: Blah incident Description: InitialAccess-Suspicious Incident Type(s): InitialAccess-Suspicious Time Incident was created: May 5, 2020 14:52:20 UTC

    We would like it to be:
    Incident Membership Change
    You have been added as a member tosfdd923.

    Incident ID: 7777
    Incident Name: Blah incident
    Description: InitialAccess-Suspicious
    Incident Type(s): InitialAccess-Suspicious
    Time Incident was created: May 5, 2020 14:52:20 UTC


    ------------------


    Thanks,



    ------------------------------
    Richard Giesige
    Security Engineer
    Oshkosh Corporation
    Oshkosh
    ------------------------------


  • 2.  RE: Notifications and line breaks

    Posted Fri May 08, 2020 03:15 PM
    You can use HTML tags like this:


    Which produces an email like this:



    ------------------------------
    Ben Lurie
    ------------------------------



  • 3.  RE: Notifications and line breaks

    Posted Fri May 08, 2020 06:06 PM
    Thanks Ben,

    It would be nice to have that mentioned in the notifications tab, as it would seem from what you guys default in the notifications that the normal line returns and such would work without needing to be HTML.

    I take it we can do full HTML code in the notifications tab (bold, italic, color, and css) or just some things will work?

    Thanks,

    Rich

    ------------------------------
    Richard Giesige
    Security Engineer
    Oshkosh Corporation
    Oshkosh
    ------------------------------



  • 4.  RE: Notifications and line breaks

    Posted Mon May 11, 2020 08:52 AM
    I don't know the full scope of HTML capabilities usable in this field.

    You are correct that it is not obvious. I have filed an internal request for making this more clear.

    Ben

    ------------------------------
    Ben Lurie
    ------------------------------