You can now pivot seamlessly from SIEM devices (Splunk or Syslog server), back into the NDR. A mechanism has been implemented to embed the alert URL directly within the alert JSON sent to the SIEM devices. Clicking this link redirects you to the corresponding alert detail page in the NDR console.
Note
If you have an NDR Console active session, you are taken directly to the Alerts Details page. If not, you are prompted to log in, and upon successful authentication, automatically redirected to the same Alert Detail page.