1. Describe your incident:
I am looking for a way to find messages related to a triggered alert.
For simple alerts it might be easy to find but e.g. for a brute force alarm or more complex scenarios it would be great to be able to have a list with the referenced messages attached that caused the alert to trigger.
Is this possible?
3. What steps have you already taken to try and solve the problem?
I’ve had a look at adding field to events but couldn’t find a way to attach the relevant source information.
4. How can the community help?
Show or propose a way on how attaching source messages to events is possible.