Additional Headers in SIEM Dashboard
complete
R
Rob Quiazon
I would like to have additional headers such as source name, source IP, and username included in the SIEM dashboard. Currently, the headers available are limited to Timestamp, Details, Organization, event.provider, event.code, and message. Adding these headers would enhance the usability and provide more detailed insights.
Nate O'Brien
marked this post as
complete
This can be accomplished via the KEEP operator which is documented in our Query KB: https://support.huntress.io/hc/en-us/articles/30113222043155-Huntress-Managed-SIEM-Log-Search-Guide