You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
msiem alarms -t LAST_3_DAYS --no_events will show events with keys: ruleName | srcIp | destIp instead of ruleMessage | sourceIp | destIp . This leads into displaying None a lot...
msiem alarms -t LAST_3_DAYS --no_events
will show events with keys:ruleName | srcIp | destIp
instead ofruleMessage | sourceIp | destIp
. This leads into displayingNone
a lot...Workaround:
Use
msiem alarms -t LAST_3_DAYS --no_events --events_fields ruleMessage sourceIp destIp
Todo: configure a new static var and assign it to events fields if
--no_events
and SIEM version >=11.xThe text was updated successfully, but these errors were encountered: