Dot-notation path into extraction_target (e.g. 'src_ip' or 'okta.data.client.ipAddress')
Indicator type: ip, domain, hash_md5, hash_sha1, hash_sha256, url, email, account
Restrict to a specific alert source (null = applies to all sources)
'normalized' (against CalsetaAlert fields) or 'raw_payload' (against source raw data)
Whether this mapping is active
Human-readable description