Is there any way to capture packet data also on ESM Report Query
For eg: I needs to generate report for firewall configuration changes which should contain the details of the change , which policy/object is modified and what is the change etc.
The ESM is designed to work with parsed structured data. You will want to make sure all key details are parsed into your event and then you can include it in reports.
Thanks for information
I believe for alarms this is possible by copy packet data option and for report we have to run a query to the fields available on ESM. Since the ESM have only the parsed data available we needs to do a custom parsing to add any more field from packet data