I created the following correlation alerts in ES with Notable
Index=fw (dest_ip=1.2.3.4 OR dest_ip=1.2.3.5)
The alerts in with cron for every 1M
Example:
At 08:00, User A ping 1.2.3.4
At 08:00, User B ping 1.2.3.3
The problem:
If two different users try to get these IPs, I will receive two notable alerts with a drill down. The drill-down will bring the two events from these two different users (mix).
What I expect to receive: 2 separate notable alerts with drill down that will receive only one event (and not the events from the other user)
Modify the notable to include the User field ($User$) in the drilldown.