In short when i have an ePO alert i need to create the same alert into theHive. At a leter stage i would also like to be able to do it the other way, for instance an alert received into theHive from misp with a particular malicious URL the same url added to the Allow and Block list of web control. The latter however is not my priority for the moment.
OpenDXL
Security Intelligence Sharing