Elastic medium stable kql
Splunk External Alerts
Generates a detection alert for each Splunk alert written to the configured indices. Enabling this rule allows you to immediately begin investigating Splunk alerts in the app.
Detection Logic
event.kind: alert and data_stream.dataset: splunk.alert Field Validations
Loading…
Comments (0)
Loading comments...