Skip to content
Discussion options

You must be logged in to vote

I fixed it after referring to the other tunings that I did before this, formatting issue

Changed it to the following:

sofilter:
    - winlog.event_data.IssuingKDC: problematicDC

which gives me the following when testing in kibana

... and (not winlog.event_data.IssuingKDC:"problematicDC") ...

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@geistchevalier
Comment options

Answer selected by geistchevalier
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants