It is recommended that you disable the Actions option when you test the trigger conditions.
The risk level defines the priority of the alert that is triggered. Risk level 1 is the lowest, and 5 is the highest.
If the Violation setting is disabled, the trigger is considered a notice and is automatically assigned a risk level of 0. Be aware that notices are not displayed on the page.
In the Trigger query area, configure the trigger conditions.
By default, the first query is cmd_user_typed = true. Remove this query as required.
After you enter a query, the system automatically runs a search and lets you know how often the trigger would have been activated over the past week.
You can configure the queries in two ways:
For more information about the available CQL values, see CQL values.
For more information about the listed properties, see CQL values.
The query you enter using one method is automatically reflected in the other.
For more information about the available actions, see Trigger actions.
At the top of the Actions list are the default actions that have been configured for the trigger type. Default actions cannot be removed from the trigger. To change the default actions, you need to have access to > page. For more information, see Default actions.
Tip: Make sure you know the order that the actions must be executed because you cannot re-order the actions after they've been added.