Alert Rules
Alert rules control which events trigger notifications and how they are delivered.
Event Types
12 event types can trigger notifications:
critical_cve— New critical vulnerability detectedhigh_cve— New high vulnerability detectedsla_breach— Vulnerability exceeded remediation deadlinescan_complete— Scan finished successfullyscan_failed— Scan failedagent_disconnected— Sensor lost connectivitycoverage_gap— Image has no recent scanexception_expiring— Attestation approaching expirationregression— Previously fixed vulnerability reappearednew_image— New image discovered in registrycve_watch_new— CVE Watch detected a new CVEcve_watch_kev— CVE added to CISA KEV catalog
Digest Modes
- Realtime — Immediate delivery on each event
- Daily — Batched daily summary
- Weekly — Batched weekly summary