Skip to content

Conversation

@Perrtyk
Copy link
Contributor

@Perrtyk Perrtyk commented Jan 12, 2026

A fix has been applied which generates an indicator event correlating to the event that triggered the detection rule.

  • Changed SDL query to include indicator event query via dataSource.name = 'indicator' and metadata.uid = 'VALUE'
  • Adjusting timing of query.

A fix has been applied which generates an indicator event correlating to the event that triggered the detection rule.
- Changed SDL query to include indicator event query via dataSource.name = 'indicator' and metadata.uid = 'VALUE'
- Adjusting timing of query.
@nate-smalls-s1 nate-smalls-s1 merged commit c365310 into Sentinel-One:main Jan 13, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants