I am trying to understand the necessity of domain specific rules...
If I am an MSSP that has customers A, B, C segmented into domains A, B, C and each domain has a dedicated processor, is there still a need to specify that a certain rule should only trigger for domain A? If all rules are designated as local then the domain specific CRE on the processor for domain A will only evaluate rules based on events specific to domain A, so there would be no need to designate a rules as only firing for domain A? Am I correct in my assumption?
#QRadar#Support#SupportMigration