Hi,
In threat intel module when adding a new threat feed source,
The feed contains also sha-256 and MD5 but I can map only one of them to the file_hash var,
There is an option to map multiple fields into the same var?
Hi @avivn,
You can add the same threat intel source twice by selecting different field as var.