Futuhal,
Does your escalation template (improper usage) fill in all the required fields for an incident to be created? (the red star is next to them on the template)
Also you can check the logs for the app (inside the app host or wherever it is installed) to see if you can gleam something else.
Rich
------------------------------
Richard Giesige
Security Engineer
Oshkosh Corporation
Oshkosh
------------------------------
Original Message:
Sent: Tue May 26, 2020 02:29 AM
From: Futuhal Annasri
Subject: Resilient App for Qradar : Automatic Escalation Problem
Hi,
I want to escalate offense with description 'VPN - User not logged in for 3 days' automatically into Resilient from QRadar using below rule:
Thank you.
------------------------------
Futuhal Annasri
------------------------------