Create Schema from Library Schema
Use a Library Schema when a reusable schema template already matches your Alert Producer.
Library Schemas are the fastest way to start because they include the schema definition before you send live traffic through 1stLine.
Before you start
You need:
- access to Alert Schemas
- an Alert Receiver destination, such as a webhook URL
- a Library Schema that matches your Alert Producer
Global Library Schemas are maintained from the public 1stLine Library Schemas repository. Organization Library Schemas are reusable templates saved inside your organization.
Create from Library
- Open Create Alert Schema.
- Choose Choose from Library.
- Select the Library Schema that matches your Alert Producer.
- Create the schema.
- Open the new schema details page.
- Review Patterns, Fields, Fingerprint Fields, Default Forward To, and forwarding behavior.
- Configure the Alert Producer to send events to the new Alert Producer Destination.
- Send a real test alert.
- Open Alert Instances and confirm the Alert Instance content, fingerprint, timeline, and actions.
After creation
The created Alert Schema belongs to your organization and receives its own Schema Token.
You can edit it like any other Alert Schema. Common changes include:
- adding or adjusting Patterns
- setting Default Forward To
- choosing Fingerprint Fields
- enabling Proxy recurrent alerts when repeated firing events should be forwarded
- adding a Transformation Template
- configuring AI Escalation Mapping
Related pages
GitHub is a third-party brand. Burava does not own, represent, or speak for GitHub.