Implementing Vulnerability Data into Data Enrichment
We recently added our Nessus vulnerability data into the SIEM and we can get the data through the dashboards just fine. What I can't seem to find (if there is any), is a way to use that to enrich data coming in using data enrichment. For example, an event comes in and we can see the threat assessment data for that device in the event details. Is this possible?