We are forwarding system network event logs via winlogbeat generated by sysmon and was attempting at dropping internal traffic events using private IP ranges.
Seems yml config does not supports wildcard hence cannot use <10.*>
Is there another way in winlogbeat to accomplish this?
Sysmon conditional grouping rules is another issue hence unable to do that.
Thank you Andrew for guiding!
I was using an old schema for the sysmon xml which did not have capability for group rules with conditions.
I had tried to use CIDR value in the winlogbeat yml config file which I believe is not supported similar to wildcards.
Pre processors is something I have noted for future use as have never used them before,not too late to use them
Finally updated the Sysmon config to have the conditional rule groups and they are working.
Thank you once again for helping out, I just love being part of this super helpful community.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.