Hi all, I want to create a Sequent template that triggers when two correlation searches triggers for the same source IP. Correlation Search 1: EDR Detection Correlation Search 2: Traffic to suspicious URL Fields of Interest from Correlation Search 1:Source IP, File Name, File Path, File Hash etc Fields of Interest from Correlation Search 2:Source IP, URL, URL_Domain, Destination IP etc How can I get the fields of interest from correlation search 2 in the sequenced events? The ‘Output Fields’ session in the Sequence template is accepting only the ‘status labels’ defined in the ‘start’ session(ie, fields from Correlation Search 1).
... View more