hello,
Could anyone assist me in creating a correlation search to detect triggered alerts across all searches. This will enable us to monitor counts and automatically notify us if any situation escalates beyond control.
Thanks
Its look like a paid course by any chance it there any link of free course ?
Hi @AL3Z ,
No, you have only to define the asset (or the identity) in the correlation search.
In other words, in the results of your CS you must have an asset (or the identity) and define this field for the risk score.
Ciao.
Giuseppe