Hi! Can you help with question, can events from asset profiler-2 be used in custom rules? We parse some fields (such as hostname and IP) from Hostname created and IP created events and want using its custom fields in our rules, add this data to reference set. But data not add to our referense set from created rule. May be this log source cant be used for it? Can log source asset profiler-2 will be used in this way?
------------------------------
Serhii Barabash
------------------------------