Hi Team,
What are the best practices for optimizing data when multiple sources such as firewalls, EDR, and telemetry are involved? Specifically:
- How should log source prioritization be determined when there is overlap?
- What factors should guide the decision on which event types to retain or ignore to minimize redundancy?
Looking forward to your insights and recommendations ?
Thank you!