Quantcast
Channel: THWACK: Popular Discussions - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5911

Modify existing LEM filter to exclude keywords

$
0
0

Using LEM 6.3.1

 

I am trying to learn this product and have stumbled upon what I thought would be an easy task - I want to take a an existing filter, clone it and then edit it to do what it is doing but to exclude certain keywords so I can reduce the sensitivity of the filter.

 

For example. I cloned the Incidents filter and now want to exclude events that have something *freebsd* or *pam* in the ToolAlias field.

This is what my traffic looks like coming in:

 

FilterEvents.PNG

And this is how my filter looks:

Filter.PNG

But yet these events keep coming in.

 

What am I doing wrong?


Viewing all articles
Browse latest Browse all 5911

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>