"In our Google SecOps environment, we're currently unable to view any IOC (Indicator of Compromise) matches . Could there be a reason for this, and what solutions might be available? And how to check Mandiant threat intelligence if it does works properly?
You need SecOps Enterprise Plus and you can learn more on this guide: Applied Threat Intelligence overview.
Let me know if that helps.
Hi @kentphelps Thank you for your answer, we have Secops Enterprise Plus and still can't see IOC matches that is important for us, do we need to open a suppert tciket for that?
Hi @kentphelps Thank you for your answer, we have Secops Enterprise Plus and still can't see IOC matches that is important for us, do we need to open a suppert tciket for that?
Support would be able to troubleshoot issues with where you are ingesting IOC log sources from or perhaps any timestamp issues.
thank you already created a support ticket.
Reply
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.