Is there any way to make TheHive parse multivalue observable?
For example, if my resulting field "hash" is from a | stats values(hash) AS hash, and the search result is:
| hash |
hash1
hash2
TheHive will not understand there are 2 hash and just parse the hash field as:
hash1 hash2
So when using Analyzer on theHive, it doesn't work.
Thanks for feedback
At the moment the alert actions does not parse multivalue fields and convert them to strings.
A work-around is to use mvexpand if you have only one multivalue field in the row.
but I am going to implement the parsing of multivalue fields in order to make proper API request.