I'm having problems with syntax on creating processor for dropping message in auditbeat.
My field process.args has value ["-bash"] if I configure processor:
processors: - drop_event: when: contains: process.args: "["-bash"]"
Auditbeat wont start. If I remove "" around value, auditbeat starts but rule isn't matching.
Any help would be much appreciated.