KQL Comprehensive Tutorial on Event Correlation Rules

You can use EQL EQL syntax reference | Elasticsearch Guide [8.5] | Elastic for event mapping. Take a look at these links:

1 Like