I am using SWOSH v2025.4.3 and have a working LA rule setup that triggers when a particular EventID is seen in a Syslog message. The Rule triggers an alert, which includes an email notification.
I would like to include certain information in the email message body. The information is highlighted by the red arrows in the screenshot.
I assume this will have to be accomplished using either a custom SQL or SWQL variable. Am I correct? If so, has anyone done this and would you be willing to share you alert formatting? Thanks so much.