Hi all,
I am trying to create a report containing the alerts generated by the ESA rules for some range of time (e.g last 5 days).
The idea is to generate a report with the alert informations shown on the picture below (Severity, Alert Name, Count, etc).
Could anybody help me with this?
Thanks in advance.
The only resolution for your ask that i'm aware of is to setup syslog notification for EACH and every alert and point to your syslog receiver on the alerts within the ESA, check the output notifications for syslog. Then take that reingestion and create a report from that information.