I want to get data from two base events into a correlated alert.
e.g. Base event will have a field - country_name
Base Event 1 - country_name - United States
Base Event 2 - country_name - Nigeria
Is it possible to get these two country details in correlated events. Since the country_name field is not identical many have told me this is not possible in arcsight.
But this is a very common scenario. Has anyone found any workaroud?? Any pointers appreciated??