Hello Team,
Greetings,
I am currently working on a detection rule that triggers when a feed is deleted. The challenge I am facing is that the event only provides the feed ID, and not the feed name.
I attempted to create a data table that populates when a feed is created, but I am unable to reference that data table field inside the rule. I also tried running a stat search; however, if I move this to a SOAR playbook, I am not sure how to handle the time correlation, since the feed could have been created at any point in time.
Could you please advise if there is a way to fetch the feed name rather than a feed_id in the same alert when a feed is deleted?
Thanks & regards,
nasef
