I'm getting hits for "Expected host not responding". I'm using a csv that has a DNS entry as well as an ip address for the host. I searched and there are recent events from the host using the exact match to the dns column entry for the given host.
How exactly does the correlation search and which entries from the assets lookup is it trying to look for or are there certain expected entries or traffic that it is looking for?
I'm still pretty new to ES and any help or guidance is much appreciated.
Thanks!