Noticed that the packetbeat_rare_server_domain ml job has a lot of noise / false positive anomalies. Most of the server.domain values are for internal url's, so I was thinking to add a filter list to limit where the rule applies and exclude '*.subdomain.domain'.
So are we able to use wildcards in ml filter lists?
(Required, array of strings) The items of the filter. A wildcard
* can be used at the beginning or the end of an item. Up to 10000 items are allowed in each filter.
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.