Hello,
Im trying to get some more queries on the workflow. I want to add source IP and destination IP for example.
DATEFORMAT (startime, 'YYYY-MM-dd HH:mm') as StartTime, NETWORKNAME(sourceip), NETWORKNAME(destinationip), CATEGORYNAME(category), LOGSOURCENAME(logsourceid), PROTOCOLNAME(protocolid),UTF8(payload),RULENAME(creeventlist)
But the workflow is not working when I add source ip and destination ip. Could be that the NETWORKNAME is innapropiate? Any documentation about thet?
Thank you.
------------------------------
Aitor Vivanco Santa Cruz
------------------------------