Skip to main content

What is product level mapping?

  • March 13, 2023
  • 4 replies
  • 3 views

Forum|alt.badge.img+1

Hi guys, I dont understand what is product level mapping. Why it is needed? is the product information comes with events?

View files in slack

4 replies

Forum|alt.badge.img+9
  • New Member
  • March 14, 2023

Some connectors may report alerts from many different products. For example, you can send Cisco AMP and O365 alerts to your SIEM and use the ElasticSearch connector to ingest both types of alerts.


Forum|alt.badge.img+1

So the product information is present in the incoming event?


Forum|alt.badge.img+9
  • New Member
  • March 14, 2023

In the case of the Cisco AMP connector, it looks like its hardcoded in its consts file

View files in slack


Forum|alt.badge.img+1

Thank you