Paul BIVIC
Paul BIVIC
https://docs.sekoia.io/xdr/develop/rest_api/configuration/#tag/intakes/operation/post_intakes_resource Needs the rights SIC_READ_INTAKES
https://docs.sekoia.io/xdr/features/detect/rules_catalog/#limiting-the-scope-of-a-rule there is nothing saying that the alert filter is limited to [the field on which CTI rules works ](https://docs.sekoia.io/xdr/features/detect/iocdetection/#which-event-fields-are-verified-when-performing-ioc-detection) [related ticket ](https://sekoia8055.zendesk.com/agent/tickets/3742)
There is an actual limitation on the host.name that are discovered. If they do not contain a letter they will not be selected by the asset discovery https://sekoia8055.zendesk.com/agent/tickets/3601 https://github.com/SekoiaLab/platform/issues/57432 [This...
We should precise that we use this : https://docs.sekoia.io/xdr/features/investigate/events_query_language/ in this page : https://docs.sekoia.io/xdr/features/detect/anomaly/#:~:text=You%20can%20use%20Sekoia.io,normal%20behavior%20in%20your%20data.
Fix https://github.com/SekoiaLab/integration/issues/516
Related to this https://sekoia8055.zendesk.com/agent/tickets/5018