Hi,
When correlating events I want to do enrichment lookups and add extra fields to the correlation event (signal).
Also we would like to be able to add fields to the correlation event from the source events that cause the trigger or populate some fields hardcoded.
How can we do this? It doesn't seem to be an option in the rules interface and enrichment is only available on ingest?
Enrichment on rule trigger and the ability to add fields on the correlation events seems to me as must haves for any SIEM solution.