Were creating an Incident report for SIEM Incidents in for the previous month, we want to capture the components events for the incident generated by the corr rules as well. However so far, weve only been able to capture details of the incident hit but not he event/s which contributed to the incident hit. Is there any way we can capture those events? Weve also tried to export from the dashboard however results are the same.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.