Import rules with event type groups
Hi,
I have to import rules to a production SIEM. Many of these rules contains a eventType IN (Group@PH_SYS_EVENT_Group).
We have noticed those conditons are broken when imported in the new SIEM and we have to remap them manually to the event type group.
My question: Is there a quicker way to make those statements working?
Thanks,
