I have a question on something I can't seem to figure out. I'm cloning a rule for the Virus Attack rule. Now in this rule I have it setup to send an email with $Eventinfo and $DetectionTime variables that were there by default. I want to also add a $DetectionIP variable into the email but I can't seem to figure out how to add this variable into the email. Help would be appreciated.
Variables are added in the email templates. So, you will need to go to Build > Groups. Find the email template you are using for that rule, or create a new one. Variables are added on the left hand side of the edit pane, then you can use them in the email text on the right hand side of the edit pane.
Hope this helps.