cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Who Me Too'd this topic

Correlated Event Log Fields Lacking

L1 Bithead

Is it me or is there no way to include the actual URL that was accessed by a network source in a "Correlation Log" event (v9.0.9 firmware) . From what I can tell on, other than a generic message like "Host visited known malware URL (X times)". It would be great to know "what" was accessed in the same event so that information can be made available easily in a SIEM vs. having to yet again correlate what the PA's saw a second time within our SIEM. Even if they added an ID field of some kind to associate the correlated event alert with the events it saw, that would make it easier to associate the events with the Correlated Event alert in a SIEM.

Who Me Too'd this topic