Hey,
I notices that our siem app has alot of missing features, like the counting query, can we have that like query something then if it pass a threashold then create a detection signal. Since only having able to query the log file to search for something but not how many time they apear is not really useful.
I know that i can use watcher to do that but watcher does not generate signal for me.
Thank.