Question

Cloud Exchange - Business Rules


Badge +5

Using the LogShipper to send logs to my SIEM.  One application in particular is very chatty and the logs it sends are not that important.   I am trying to create a business rule that will exclude that application from sending logs.   Right now, I have the default rule and one additional rule: Query: NOT (app Like "My App").  This does not work, do I have to use Regex for this?  Documentation for business rules are really poor.


0 replies

Be the first to reply!

Reply