We are currently working on some tuning in ESA alerts and came across some MSG_ids that we cannot identify
The two alerts are listed below with associated message IDs that we need descriptions for
- Multiple Logs from MsgID Set with Same SourceIP DestinationIP
Msg_id in the syntax of the rule are ('00490' , ' 00490:08',' 00490:21' , '00004:16', ' 00490:01', '00490:07' , '00490:08' , '106001','106001:01','106002'
-Multiple Unique Logs from MsgID Set with Same Source and Destination IP
Msg_id in the syntax of the rule are ('00490', '00490:06','00490:08','00490:21')