I am curious to see if there is a way for email of an investigation or alert to show the matching log it found from the rule logic. I know the basic detection rules can do it and I really like that feature. I am wondering if the regular rules can do that too
this is currently not possible, this would be an enhancement request
David