Question
Finding out what actually triggered IDS Sensor (HTTP.URI.SQL.Injection)
Our current configuration successfully blocks HTTP.URI.SQL.Injection and other attacks.
However I would like to understand what the attackers are trying to achieve; is there anyway of viewing the raw data that actually triggered this sensor?
