1) The from address can be set in the Admin tab -> System Settings. It's near the top "Alert Email from Address". You may also find this useful https://www.ibm.com/docs/en/qsip/7.5?topic=notifications-configuring-event-flow-custom-email
2) There's no test for magnitude because it is a dynamically calculated attribute of the offense rather than an assigned one. It is made up of severity, credibility and relevance. So you have to test for them individually.
3) really only by inference from the rules and events that contribute to the offense. You can search for events associated with an offense and from there aggregate on Networks. Or search by rule and find the events that hit a rule or BB that uses a certain reference data collection in its tests.