Skip to content
Discussion options

You must be logged in to vote

I had to modify my syntax to look like the following. I think this is now working for me to filter out users for the same alert.

sofilter:
  - winlog.event_data.SubjectUserName: _svc365

If I just use "SubjectUserName" it doesn't work correctly. In my case, I should get zero results when I test in Kibana and so far it looks like it's finally filtering out correctly.

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
2 replies
@oneCrazyAdmin
Comment options

@defensivedepth
Comment options

Comment options

You must be logged in to vote
0 replies
Answer selected by oneCrazyAdmin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
2.4
Labels
None yet
3 participants