050-SEPROSIEM-01 · Question #53
To automatically send alerts to Event Explorer when an associated alert is triggered, use the
The correct answer is C. Task Create Output Action. The Task Create Output Action is the RSA enVision mechanism that automatically forwards a triggered alert as a new entry into Event Explorer.
Question
To automatically send alerts to Event Explorer when an associated alert is triggered, use the
Options
- AEvent trace Library
- BGlobal table data model
- CTask Create Output Action
- DTask Escalate Output Action
How the community answered
(56 responses)- A4% (2)
- B9% (5)
- C82% (46)
- D5% (3)
Why each option
The Task Create Output Action is the RSA enVision mechanism that automatically forwards a triggered alert as a new entry into Event Explorer.
The Event Trace Library is a reference component used for event tracing and parsing, not an output action for routing alerts to Event Explorer.
The Global Table Data Model defines data structure schemas used across the system and has no role in routing or forwarding alert notifications.
The Task Create Output Action is configured on an alert rule and fires whenever that alert is triggered, automatically creating a corresponding incident or task record that is sent to Event Explorer. This enables centralized tracking of alert-driven incidents without manual intervention. It is the specific output action type designed for this initial alert-to-incident routing workflow.
The Task Escalate Output Action is used to escalate an already-existing task or incident to a higher priority or different owner, not to initially create or send an alert to Event Explorer.
Concept tested: RSA enVision Task Create Output Action for alert routing
Topics
Community Discussion
No community discussion yet for this question.