Versions (relevant - OpenSearch/Dashboard/Server OS/Browser):
Dashboards 2.15
Opensearch 2.15
Describe the issue:
I have my syslog index in which I hold system logs from several linux machines. Using alerting I created a few monitors that check activities in these linux machines.
When an alert has been triggered (for example when a host fails SSH 3 times) using my monitor I can only see that alert has been triggered but have no idea about the exact host machine (basically the log) that the activity took place in which is a super crucial information. Is there any way I can implement this, I checked out Detectors but that also doesnt provide this functionality as far as I can see.
I think if this feature hasnt been implement yet it makes Opensearch not a good alternative for a SIEM this that crucial.
Relevant Logs or Screenshots: