Skip to content

Terms filter not working #297

Locked Answered by jertel
ngms17 asked this question in Q&A
Jun 26, 2021 · 2 comments · 1 reply
Discussion options

You must be logged in to vote

Change your filter to:

filter:
- terms:
    rule.category: ["Denial of Service", "Executable code was detected", "A Network Trojan was detected", "Detection of a Denial of Service Attack", "Targeted Malicious Activity was Detected", "Exploit Kit A$
- terms: 
    suricata.eve.in_iface: ["enp3s0f0", "enp3s0f1"]

NOTE: This is an AND query, so both terms must match at least one entry in their value list.

Replies: 2 comments 1 reply

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
1 reply
@nsano-rururu
Comment options

Answer selected by jertel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
3 participants