Hi geeks, I integrated the TheHive and Cortex with Splunk ES for getting some alerts after triggering the correlation search rule. According to the attached Image-01, please help me for filling the correct values for "Data field name" and "Datatype field name". Also, Do I have to specify the exact name according to what is in the Cortex to identify the "Analyzers"? Image-01: Image-02: image-03: Regards, Amir
... View more
Please try to use some other port than 10514, for example 10515 :
[udp://10515]
sourcetype = flowintegrator
disabled = 0
and configure the Optimizer to send to 10515.
... View more