Hello everyone,
I have added an IP on local_intel_ip.csv and it now appears on Threat Artifact panel. The correlation search "Threat Activity Detected" is enabled with Adaptive Response Actions a Notable and Risk Analysis.
A notable event was triggered with this IP as destination IP, but the aforementioned Notable (Threat Activity Detected) was never triggered.
Any idea on what I might have done wrong?
Thank you in advance.
Chris
After troubleshooting I found the solution:
I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.
After troubleshooting I found the solution:
I had the Acceleration of Alerts datamodel disabled. Once enabled, the alerts started popping up to my Incident Review console.