Add (any) threat level/priority metadata from the correlation source to the event
Then correlation is done towards the MISP-data, there is typically a threat level / priority indicator etc. bound to the MISP-event. It would be useful if that could be added to the correlation too, to help the analyst with prioritization of the correlated events.