Hello,
I recently configured an Indicator Matching Rule that creates alarms if any indicator is found. The issue with this is that the indicator are matched partially. For instance if I have the indicator something.q77.eu and a log entry of ecsc2025.eu it results in a match bc "eu" of the indicator is found in the logentry.
Any way to get an exact match?
Best Regards.