Hi all,
I want to create a Sequent template that triggers when two correlation searches triggers for the same source IP.
How can I get the fields of interest from correlation search 2 in the sequenced events? The ‘Output Fields’ session in the Sequence template is accepting only the ‘status labels’ defined in the ‘start’ session(ie, fields from Correlation Search 1).