In ES, I'm trying to create a correlation search where I establish groups on a 'List and Lookups' asset list (under the Owner column) and if that group matches any critical incidents from our AV, then an alert is generated. However, I cannot get the group names I created to populate in the AV logs so the alert doesn't work.
I've created a Lookup Table, a Lookup Definition and created that .csv list in 'Lists and Lookups' with all necessary rights for all items. However, the data still doesn't populate.
Am I doing something wrong or looking at this in the wrong way?