Help Center/ SecMaster/ User Guide/ Playbook Overview/ Application Defense Alarms Are Associated With Historical Handling Information
Updated on 2026-02-06 GMT+08:00

Application Defense Alarms Are Associated With Historical Handling Information

Playbook Overview

If SecMaster receives new alerts from WAF within 15 days and there are closed WAF alerts of the similar type, the Application Defense Alarms Are Associated With Historical Handling Information playbook will add the comment for the closed WAF alerts to the comment area of the new similar WAF alerts. This playbook is applied to alerts only. Attacks cannot trigger it. For details about the differences between alerts and attacks, see Overview.

If two WAF alerts meet any of the following conditions, they are similar alerts:

  • They have the same source IP address.
  • They are generated for the same attacked domain names.
  • They belong to the same alert type.

This playbook is enabled by default. There is no need for you to configure or enable it. This playbook is triggered when SecMaster receives new alerts from WAF and the new alerts are similar to a closed WAF alert.

Prerequisites

Limitations and Constraints

  • The alert data source is WAF.

Implementation Effect

After the playbook is triggered, SecMaster adds the closure comments for similar closed alerts to new WAF alerts in SecMaster.

  1. Log in to the SecMaster console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. In the navigation pane on the left, choose Workspaces > Management. In the workspace list, click the name of the target workspace.

    Figure 1 Workspace management page

  4. In the navigation pane on the left, choose Threats > Alerts.

    Figure 2 Alerts

  5. On the Alerts page, filter WAF alerts by data source and click the name of a new WAF alert to go to the details page.
  6. If there are closed similar alerts, the closure comments for the closed alerts will be automatically added to the comment area on the details page of the new WAF alert. If two WAF alerts meet any of the following conditions, they are similar alerts:

    • They have the same source IP address.
    • They are generated for the same attacked domain names.
    • They belong to the same alert type.