Hi, How can I control the log entry being pushed as alerts in alertsui? I configured bro device and using threat feed to find whether source IP is malicious or not. Only entries with malicious ip should be sent to the ui and now all entries are going to Metron alertsui.please help.
-Jai