.yml
files.
The supported attributes are: owner, subscribers, description, tags.
You can configure and customize your alerts by configuring:
custom channel, suppression interval, alert fields (for test alerts only), alert grouping, alert filters.
edr monitor
command to send alerts.
If you want continuous alerting, you will need to orchestrate the CLI.