'Fetching indicator details from elastic detection alerts
I'm trying to fetch the indicator details from an elastic detection alert, looks like there is no API or proper query to do the same. I'm looking to fetch the details like sourceip, destinationip etc.. All I see is, these information are available at the event level. But there is no relation between an alert and the event.. Plz correct me if I'm doing something wrong
Sources
This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.
Source: Stack Overflow
| Solution | Source |
|---|
