I want to drop events with the following conditions:
"If (event.id=(x or y) AND user.name=a) OR (event.id= z and process.name = 'cmd.exe') "
But I just can't figure out the conditions.
I want to drop events with the following conditions:
"If (event.id=(x or y) AND user.name=a) OR (event.id= z and process.name = 'cmd.exe') "
But I just can't figure out the conditions.
Do you have an example of your attempt? How far have you reached. Can you share the error too, please?
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.