EQL - Alert when Follow up event doesn't occur

Hey there @lilow! :wave: Welcome to the community! :tada: :slightly_smiling_face:

So unfortunately it looks like there is no easy way to do this at the moment. There was a similar thread over here that mentions there is work underway to support this though.

Though as mentioned by this other user, you may be able to implement this another way depending on your configuration.

Hope this helps!

Cheers!
Garrett

edit: For reference, this looks like the public issue/PR you'll want to follow for when this feature will be available.

2 Likes