Hi, I have to import rules to a production SIEM. Many of these rules
contains a eventType IN (Group@PH_SYS_EVENT_Group). We have noticed
those conditons are broken when imported in the new SIEM and we have to
remap them manually to the event type gro...
I am having a very similar issue here. I have been reviewing the
collectAndSetAttrByJsonArray function to extract the objects form the
array. To say the least, that function is not weel eplained in the
documentation but it looks like it has other fun...
You are leaving our website
You are leaving our site and we cannot be held responsible for the content of external websites