Hello,
Noticed that the packetbeat_rare_server_domain ml job has a lot of noise / false positive anomalies. Most of the server.domain values are for internal url's, so I was thinking to add a filter list to limit where the rule applies and exclude '*.subdomain.domain'.
So are we able to use wildcards in ml filter lists?
Grtz
Willem