CollectionType

The type of the collection which will indicate which other fields are relevant. For example, detection finding collections will populate the detection field. Findings that evolve into investigations will populate the investigation field.

Enums
COLLECTION_TYPE_UNSPECIFIED An unspecified collection type.
TELEMETRY_ALERT An alert reported in customer telemetry.
GCTI_FINDING A finding from the Uppercase team.
UPPERCASE_ALERT
RULE_DETECTION A detection found by applying a rule.
MACHINE_INTELLIGENCE_ALERT An alert generated by Chronicle machine learning models.
SOAR_ALERT An alert coming from other SIEMs via Chronicle SOAR.