I have some ability that i require SIEM do.
i want to make a query and then if that query match then the second query will be call to search for that specific case since not all security case that happen in single log file but multiple log file.
If that is not available then please make it a feature for SIEM.
You can create sequences with EQL. take a look at this.
Yes thanks you for your respond.
But i want to also know how to put that in to elastic SIEM since i dont really see a way to put EQL in any other than the console.
You can use it in SIEM after 7.10 update. take a look at this.