Data Export actions let you automatically export data whenever Sightline detects an attack that matches the policy rule you add it to.
You can learn how to create data export actions with this article.
These actions only support acccount-related events.
Your data export action has been created. Next, be sure to add it to a policy rule.
Once you have a data export action, we recommend adding it to a policy rule.
Be sure your policy rule’s application and event type match the ones you chose above. Otherwise, the action won’t appear when you try to add it to the rule.

Now, whenever Sightline detects an attack that matches the conditions in that policy rule, it will send a data request about that attack to your chosen integration.