Open praveens862 opened 2 years ago
Hi , I am looking correlation rule like if from an blacklist IP ,I get accept connection on firewall and from same IP any activity detected on endpoint.
look https://github.com/Yelp/elastalert/issues/3178
Hi @nsano-rururu I can't find this issue in 3178 can you suggest something else
Hi , I am looking correlation rule like if from an blacklist IP ,I get accept connection on firewall and from same IP any activity detected on endpoint.