Hi Community,
I have these alerts on EDR and I want to create a correlation search to show these alerts on the Splunk
Hi @m_khatibo88 ,
could you share the two (or only one?) searches generating the two alerts?
Then, what do you mean with "correation"? do you want one search where there are both the results or what else?
Ciao.
Giuseppe