- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problem in using Cortex as Response Action in Splunk ES correlation search rules!

zargaran
New Member
05-23-2022
03:12 AM
Hi geeks,
I integrated the TheHive and Cortex with Splunk ES for getting some alerts after triggering the correlation search rule. According to the attached Image-01, please help me for filling the correct values for "Data field name" and "Datatype field name".
Also, Do I have to specify the exact name according to what is in the Cortex to identify the "Analyzers"?
Image-01:
Image-02:
image-03:
Regards,
Amir
