The following table describes token variables for customizing Advanced Threat Activity event notification messages.
For the list of standard token variables supported by all event notifications, see Standard Token Variables.
| 
 Variable  | 
 Description  | 
|---|---|
| 
 %hostIP%  | 
 Depending on the traffic direction, %hostIP% is IP address determined by Deep Discovery Inspector: 
  | 
| 
 %group%  | 
 Name of the subnetwork  | 
| 
 %START_TIME%  | 
 Start time  | 
| 
 %END_TIME%  | 
 End time The start and end times define the time range interval. When logs are received during a certain interval, Apex Central calculates those logs. If the alert criteria is met, Apex Central counts the logs. %START_TIME% is the start time of the interval and %END_TIME% is the end time of the interval. The length of the interval is determined by the period threshold in the alert settings.  | 
| 
 %detections%  | 
 Number of detections For example: Event: High risk Virtual Analyzer detections IP address: %hostIP% Host name: %computer% Group: %group% Time range: %START_TIME% - %END_TIME% Detections: %detections%  | 
		