I'm attempting to add some new fields to leverage the Asset Extraction for our Notables. As of today, we have what appear to be the default values: src,dest,dvc,orig_host. From my experience, when src/dest are present in a search, the priority value is automatically assigned to the notable, and I believe that functionality is happening via this setting. I'm wanting to add the src_ip/dest_ip fields that are leveraged in most of our searches to obtain the priority value from our assets inventory. However, after running a test by adding dest_ip to the entries with a search with dest_ip populated, it didn't pull the priority value as expected. I'm wondering if there maybe a piece I'm missing that I should verify or if there may have been replication time I needed to account for.
... View more