Hi, I need to create one rule, when my Packet Decoder detects one threat
following by my Log Source (such as Firewall) action such DROP/BLOCK. I
did like this, but the rule is wrong. Could you help me? SELECT * FROM
Event( /* Statement: ioc */ (isOne...