Non Enterprise Security Splunk users
Hi Please share some info on how you are running your setup. We are currently using the TA-Demisto splunk app to push the alerts to the XSOAR but having issues with excessive incidents in XSOAR being created when we use the |table in our searches and havent been able to figure this out. Thanks in advance for tips and tricks on this subject.




