Community,
I am looking to deploy the Hunt and Investigation Feeds. The instructions talk about adding meta keys to the concentrator, but no details are given on how to add those meta keys to the decoders as well. Aren't we supposed to add them in both locations? Below I have added a link to the Investigations article
Thanks
No, they are not added to the index-decoder-custom.xml.
That file would only be used if I needed to manually add a meta key that wasn't created by a parser or a feed. I used to only do that for application rules going into a custom meta key's.
However, there are ways to have those keys for application rules automatically added to the index without having to modify the custom index file. Instead of selecting a key to write meta for an application rule, you could just write the name of the custom key.
Chris
Sent from my mobile device