When creating or editing a correlation search in Enterprise Security, Is there any way to use multiple fields on the Risk Analysis response action?
As an example, I have a correlation search which I want to increase risk to both src and dest. I tried to separate this two fields using comma, but it does not seen to work.
The UI does not support that.
You can review the docs on how to edit risk on another object by also doing it in your SPL search. Look at the section calling the sendalert command.
View solution in original post
Thanks, I think this will help me.