2022-11-16 09:52 PM
I want to create an ESA rule to alert when an IP indicator is seen in NetWitness.
How do I do this?
2022-11-16 11:36 PM
I created a CSV recurring feed that generates meta into the 'feed.name' meta key.
Then I created an ESA rule that alerted on the existence of the feed.name key.
I thought I could create a simple context hub list since I only have 1 IP I want this alert on, but I couldn't figure out how to create the ESA rule to alert if ip.src or ip.dst exists and is on the contexthub list.
2022-11-16 11:36 PM
I created a CSV recurring feed that generates meta into the 'feed.name' meta key.
Then I created an ESA rule that alerted on the existence of the feed.name key.
I thought I could create a simple context hub list since I only have 1 IP I want this alert on, but I couldn't figure out how to create the ESA rule to alert if ip.src or ip.dst exists and is on the contexthub list.