I'm running into an issue with Enterprise Security (ES) - correlation with event types with Add-ons.
The example I have is with the Windows Add-on. I have version 5.0 in the environment but with ES I have version 4.8.4 - will the correlation that ES works off of with the Add-on cause issues in finding the data?
Answered my own question - it's important with the changes of tags and event types - specifically with this situation and the windows add-on.
Answered my own question - it's important with the changes of tags and event types - specifically with this situation and the windows add-on.