
The type of the collection which will indicate which other fields are relevant. For example, detection finding collections will populate the detection field. Findings that evolve into investigations will populate the investigation field.

COLLECTION_TYPE_UNSPECIFIED An unspecified collection type.
TELEMETRY_ALERT An alert reported in customer telemetry.
GCTI_FINDING A finding from the Uppercase team.
RULE_DETECTION A detection found by applying a rule.
MACHINE_INTELLIGENCE_ALERT An alert generated by Chronicle machine learning models.
SOAR_ALERT An alert coming from other SIEMs via Chronicle SOAR.