I'm trying to work with the Incident Management module in 10.6, and I can't find documentation that properly explains its interaction with ESA alerts.
- Why do correlation rules refer to Severity as a numeric value as opposed to a string? (ESA severities are Low, Medium, High, and Critical).
- Where is the "Alert Rule ID" defined for an ESA alert?
Thanks