Hello guys,
I have a theoretical question for my understanding of SecOps behavior when namespaces are involved.
Let’s say I have a SecOps instance with multiple namespaces configured, and matching environments configured on the SOAR part (1 to 1 with namespaces). I also have a multi-event rule that monitors events regardless of namespace. The rule also has a `match` field that is not an asset.
My question:
If this multi-event rule triggers based on data from multiple namespaces, in what environment will the alert land ?


