I am looking for some general guidelines or pointers on how to best determine which Even Fields from the Event & Event Groups to use when building nDepth queries and correlation rules? I find I often spend a lot of time trying to figure this out and have come to the conclusion that there has got to be a better way.
Thanks in advance for any suggestions!