Using the LogShipper to send logs to my SIEM. One application in particular is very chatty and the logs it sends are not that important. I am trying to create a business rule that will exclude that application from sending logs. Right now, I have the default rule and one additional rule: Query: NOT (app Like "My App"). This does not work, do I have to use Regex for this? Documentation for business rules are really poor.
Sign up
Already have an account? Login
Sign in or register securely using Single Sign-On (SSO)
Employee Continue as Customer / Partner (Login or Create Account)Login to the community
Sign in or register securely using Single Sign-On (SSO)
Employee Continue as Customer / Partner (Login or Create Account)Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
Reference documentation:



